AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-101905.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 7.6CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 30, 2026

Disclosure summary

## Summary Axios' Node HTTP adapter can act as a read-side prototype-pollution gadget for Node's sensitive `createConnection` request option. The adapter creates a null-prototype options object, but Node's HTTP client can copy or normalize request options into ordinary objects before connection creation. If `Object.prototype.createConnection` has been polluted elsewhere in the same process, Node can call the inherited function and create a socket to an attacker-controlled endpoint. Axios does not create the prototype pollution source. The vulnerability is that axios does not set an own safe value for a sensitive transport option before handing options to Node. ## Impact Given a prior same-process prototype-pollution primitive, an attacker can redirect later axios Node HTTP requests at the socket layer while the request URL and axios config still appear to target the legitimate origin. The attacker-controlled endpoint can receive request headers and bodies, including Authorization headers, cookies, API keys, and service credentials, and can return attacker-controlled responses to the application. This can bypass application destination validation that checks the URL before calling a

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-m8m8-qj5v-23w3

Open original source · Updated Sep 30, 2026

Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection

Source severity: HIGH / 7.6

EcosystemPackageAffected rangeFirst patched
npmaxios>= 1.15.2, < 1.20.01.20.0

Original records & references

PUBLISHED 2026-09-30T11:32:51-04:00
MODIFIED 2026-09-30T11:32:57-04:00
INGESTED 2026-10-06T11:43:09-04:00