TL;DR
Axios released updates to patch ten Axios security vulnerabilities. Specifically, these bugs include prototype pollution and denial-of-service risks. Therefore, you should update to version 1.20.0 immediately.
- Total: 10 CVEs
- Severity: 6 High · 4 Medium
- Actively exploited: None confirmed
- Highest severity: 8.3 (High · CVSSv4) — CVE-2026-101909
- Action: Apply the latest security updates now
Track every Apple CVE the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv4) | Type | Status |
|---|---|---|---|
| CVE-2026-101909 | 8.3 | Prototype Pollution Gadget in toFormData Options | Not exploited |
| CVE-2026-101906 | 8.2 | ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location | Not exploited |
| CVE-2026-101903 | 8.2 | ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) | Not exploited |
| CVE-2026-101901 | 8.2 | Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization | Not exploited |
| CVE-2026-101905 | 7.6 | Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection | Not exploited |
| CVE-2026-101907 | 7 | maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF | Not exploited |
| CVE-2026-101908 | 6.9 | Prototype pollution gadget in fetch adapter can alter outbound requests | Not exploited |
| CVE-2026-101904 | 6.9 | Header Injection via Inherited headers After Minimal Interceptor | Not exploited |
Why It Matters
These Axios security vulnerabilities expose the Node.js HTTP adapter to major risks. Indeed, attackers could extract credentials or crash your servers. Furthermore, SSRF protections fail under certain HTTP adapter configurations. Official advisories do not provide exact affected user counts. However, Axios remains a massively popular package across the internet. Consequently, millions of applications could be at risk if left unpatched.
How The Attack Works
Many flaws rely on prototype pollution gadgets. First, a separate bug must pollute the process memory. Next, Axios reads these polluted properties during request formatting. Consequently, this alters headers, form data, or socket connections. Other bugs involve complex regular expressions. For instance, long strings of slashes in URLs freeze the event loop. Additionally, the fetch adapter ignores redirect limits. Thus, attackers can bypass security checks. In another case, HTTP/2 session initialization drops critical outbound proxy state. This directly allows unauthorized internal network access.
Exploitation Status
Researchers published proof-of-concept demonstrations for these bugs. However, no active exploitation in the wild is confirmed yet.
Affected Versions
The flaws affect Axios versions up to 1.19.x. Specifically, issues impact the 0.x and 1.x release lines.
Patch And Mitigation Steps
You must upgrade Axios to version 1.20.0 to fix these flaws. Also, version 0.34.0 fixes certain older branches. Alternatively, avoid passing untrusted data to request options. Furthermore, disable HTTP/2 for untrusted destinations until you can update. Finally, you can review the official reports at the Axios security advisories page.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!