CVE-2026-101905

Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process prototype-pollution flaw places a function on Object.prototype.createConnection. Node resolves and invokes the inherited createConnection socket factory, allowing the attacker-controlled function to select the transport endpoint. The attacker endpoint can receive request headers and bodies, including credentials, and return attacker-controlled responses while the URL appears legitimate. This issue is fixed in version 1.20.0.

  • Published Sep 28, 2026
  • CVSS 7.6 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

In the news

CVE-2026-101905 at the National Vulnerability Database