CVE-2026-101909: fallo de gravedad alta en axios
Axios: Prototype Pollution Gadget in axios toFormData Options
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.3epss 0.4%
probabilidad de explotación
0.4%top 73% de las CVE
explotación observada
noninguna fuente lo reporta
Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution. A separate same-process prototype-pollution flaw supplies inherited dots, indexes, metaTokens, maxDepth, visitor, or Blob values before object serialization. The inherited options alter toFormData field naming and data interpretation, maxDepth can force request failure, Blob changes value handling, and a polluted visitor can execute when an attacker already has the stronger ability to inject a function. Serialized field naming and data interpretation can change, maxDepth can cause request failure, Blob can alter value handling, and a polluted visitor can execute under the stronger function-injection primitive. This issue is fixed in versions 0.34.0 and 1.20.0.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Productos afectados
axios · axiosCVEs relacionadas — axios
En el mismo producto, de las más peligrosas a las menos.
CVE-2019-10742—CVE-2019-10742EPSS 6.1%CVE-2026-25639HIGHAxios affected by Denial of Service via __proto__ Key in mergeConfigEPSS 2.0%CVE-2026-40175MEDIUMAxios has Unrestricted Cloud Metadata Exfiltration via Header Injection ChainEPSS 1.3%CVE-2025-62718MEDIUMAxios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRFEPSS 1.2%CVE-2025-58754HIGHAxios is vulnerable to DoS attack through lack of data size checkEPSS 1.1%CVE-2026-44495HIGHAxios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config MergeEPSS 1.0%
Referencias
https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39ahttps://github.com/axios/axios/commit/d29be181f85f6fe93397a07b1f69606d9622637bhttps://github.com/axios/axios/pull/11141https://github.com/axios/axios/releases/tag/v0.34.0https://github.com/axios/axios/releases/tag/v1.20.0https://github.com/axios/axios/security/advisories/GHSA-x97p-jq2g-jp4f