Looking for the vulnerability index of Invicti's legacy products?
axios : Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Inje (CVE-2026-101900) - Vulnerability Database

axios : Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Inje (CVE-2026-101900)

Description

Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormData headers. A separate same-process prototype-pollution flaw supplies an array or non-plain class instance whose inherited properties make it appear FormData-like; plain objects are blocked. The inherited getHeaders function can return attacker-controlled headers that resolveConfig merges into a fetch

Related Vulnerabilities