AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-101909.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 8.3CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 30, 2026

Disclosure summary

## Summary Axios form serialization reads `visitor`, `maxDepth`, `dots`, `indexes`, `metaTokens`, and `Blob` from an internal options object without own-property guards. When `Object.prototype` has been polluted elsewhere in the same process, those inherited values can change how axios serializes multipart and URL-encoded request bodies. Axios does not create the prototype pollution source. This is a read-side gadget: axios turns an existing same-process pollution condition into altered request serialization or request failures. ## Impact The impact depends on which property is polluted and which axios serialization path the application uses. Polluted `dots`, `indexes`, or `metaTokens` can change field names and cause the receiving service to parse different data than the caller intended. Polluted `maxDepth` can cause nested form submissions to throw `ERR_FORM_DATA_DEPTH_EXCEEDED`, producing request-level or service-level denial of service for affected workflows. Polluted `visitor` can execute as the serializer visitor if an attacker can place a function on `Object.prototype`, but that condition generally implies a stronger same-process code-execution or malicious-dependency primit

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-x97p-jq2g-jp4f

Open original source · Updated Sep 30, 2026

Axios: Prototype Pollution Gadget in axios toFormData Options

Source severity: HIGH / 8.3

EcosystemPackageAffected rangeFirst patched
npmaxios>= 0.28.0, < 0.34.00.34.0
npmaxios>= 1.15.1, < 1.20.01.20.0

Original records & references

PUBLISHED 2026-09-30T11:02:45-04:00
MODIFIED 2026-09-30T11:02:48-04:00
INGESTED 2026-10-06T11:43:09-04:00