Disclosure summary
## Summary Axios request interceptors may return a replacement config object. If an interceptor returns a plain object without an own `headers` property, `dispatchRequest()` later evaluates `config.headers` and can resolve an inherited `Object.prototype.headers` value. In a process where another vulnerability has polluted `Object.prototype.headers`, axios can send attacker-controlled headers. Axios does not create the prototype pollution source, and the interceptor itself is trusted caller code. The vulnerable behavior is the post-interceptor axios config read that reopens a prototype-pollution gadget after earlier null-prototype config hardening. ## Impact An attacker with a prior same-process prototype-pollution primitive can inject headers into affected axios requests when the application uses an interceptor that rebuilds config and omits headers. Depending on the target service, injected headers can affect cache behavior, conditional requests, metadata services, or application-specific authorization and routing logic. The issue is conditional and should not be described as affecting every interceptor or every request. ## Affected Functionality Affected: - Request interceptor ch
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-j8rh-479h-cp32
Open original source · Updated Sep 30, 2026
Axios: Header Injection via Inherited headers After Minimal Interceptor
Source severity: MEDIUM / 6.9
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | axios | >= 1.0.0, < 1.20.0 | 1.20.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-30T11:35:14-04:00
MODIFIED 2026-09-30T11:35:17-04:00
INGESTED 2026-10-06T11:43:09-04:00