Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process prototype-pollution flaw places a function on Object.prototype.createConnection. Node resolves and invokes the inherited createConnection socket factory, allowing the attacker-controlled function to select the transport endpoint. The attacker endpoint can receive request headers and bodies, including credentials, and return attacker-controlled responses while the URL appears legitimate. This issue is fixed in version 1.20.0. | |
| Title | Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection | |
| Weaknesses | CWE-1321 CWE-441 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-28T17:31:00.916Z
Reserved: 2026-09-28T15:55:37.907Z
Link: CVE-2026-101905
No data.
Status : Received
Published: 2026-09-28T18:17:18.923
Modified: 2026-09-28T18:17:18.923
Link: CVE-2026-101905
No data.
OpenCVE Enrichment
No data.