AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-101904.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 6.9CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 30, 2026

Disclosure summary

## Summary Axios request interceptors may return a replacement config object. If an interceptor returns a plain object without an own `headers` property, `dispatchRequest()` later evaluates `config.headers` and can resolve an inherited `Object.prototype.headers` value. In a process where another vulnerability has polluted `Object.prototype.headers`, axios can send attacker-controlled headers. Axios does not create the prototype pollution source, and the interceptor itself is trusted caller code. The vulnerable behavior is the post-interceptor axios config read that reopens a prototype-pollution gadget after earlier null-prototype config hardening. ## Impact An attacker with a prior same-process prototype-pollution primitive can inject headers into affected axios requests when the application uses an interceptor that rebuilds config and omits headers. Depending on the target service, injected headers can affect cache behavior, conditional requests, metadata services, or application-specific authorization and routing logic. The issue is conditional and should not be described as affecting every interceptor or every request. ## Affected Functionality Affected: - Request interceptor ch

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-j8rh-479h-cp32

Open original source · Updated Sep 30, 2026

Axios: Header Injection via Inherited headers After Minimal Interceptor

Source severity: MEDIUM / 6.9

EcosystemPackageAffected rangeFirst patched
npmaxios>= 1.0.0, < 1.20.01.20.0

Original records & references

PUBLISHED 2026-09-30T11:35:14-04:00
MODIFIED 2026-09-30T11:35:17-04:00
INGESTED 2026-10-06T11:43:09-04:00