CVE-2026-101902Medium· 6.9▾ SunlitAxios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If another vuln…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 38 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If another vulnerability in the same process pollutes Object.prototype.method, calls such as axios.request({ url }) and axios({ url }) can send a state-changing HTTP method instead of the expected default GET. Axios does not create the prototype pollution source. This is a read-side gadget in axios request dispatch. This issue is fixed in version 0.34.0 and 1.20.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-101909High· 8.3Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101908Medium· 6.9Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101904Medium· 6.9Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101905High· 7.6Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101900Medium· 6.9Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101906High· 8.2Axios is a promise-based HTTP client for the browser and Node.js