Looking for the vulnerability index of Invicti's legacy products?
axios : Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') V (CVE-2026-101908) - Vulnerability Database

axios : Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') V (CVE-2026-101908)

Description

Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but then calls fetch with the original fetchOptions. A separate same-process prototype-pollution flaw populates Object.prototype.headers so fetchOptions.headers resolves through inheritance. The inherited fetchOptions.headers value overrides the sanitized Request headers through the second argument to fetch after Request construction. At

Related Vulnerabilities