CVE-2026-101909: high-severity vulnerability in axios
Axios: Prototype Pollution Gadget in axios toFormData Options
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.3epss 0.4%
exploitation probability
0.4%top 73% of all CVEs
observed exploitation
nono source reports it
Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution. A separate same-process prototype-pollution flaw supplies inherited dots, indexes, metaTokens, maxDepth, visitor, or Blob values before object serialization. The inherited options alter toFormData field naming and data interpretation, maxDepth can force request failure, Blob changes value handling, and a polluted visitor can execute when an attacker already has the stronger ability to inject a function. Serialized field naming and data interpretation can change, maxDepth can cause request failure, Blob can alter value handling, and a polluted visitor can execute under the stronger function-injection primitive. This issue is fixed in versions 0.34.0 and 1.20.0.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Affected products
axios · axiosRelated CVEs — axios
In the same product, most dangerous first.
CVE-2019-10742—CVE-2019-10742EPSS 6.1%CVE-2026-25639HIGHAxios affected by Denial of Service via __proto__ Key in mergeConfigEPSS 2.0%CVE-2026-40175MEDIUMAxios has Unrestricted Cloud Metadata Exfiltration via Header Injection ChainEPSS 1.3%CVE-2025-62718MEDIUMAxios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRFEPSS 1.2%CVE-2025-58754HIGHAxios is vulnerable to DoS attack through lack of data size checkEPSS 1.1%CVE-2026-44495HIGHAxios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config MergeEPSS 1.0%
References
https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39ahttps://github.com/axios/axios/commit/d29be181f85f6fe93397a07b1f69606d9622637bhttps://github.com/axios/axios/pull/11141https://github.com/axios/axios/releases/tag/v0.34.0https://github.com/axios/axios/releases/tag/v1.20.0https://github.com/axios/axios/security/advisories/GHSA-x97p-jq2g-jp4f