OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-101909

HIGH · CVSS 8.3 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Axios versions 0.28.0 to 0.34.0 and 1.15.1 to 1.20.0 are vulnerable to prototype pollution, which can lead to altered field naming and data interpretation during serialization, potential request failures, and altered value handling for Blob objects. This vulnerability allows attackers to exploit inherited serialization options, potentially executing malicious code if they already have the ability to inject functions. Developers using affected versions should prioritize upgrading to versions 0.34.0 or 1.20.0 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-101909
Severity
HIGH
CVSS
8.3
EPSS
0.35%

Original NVD Description

Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution. A separate same-process prototype-pollution flaw supplies inherited dots, indexes, metaTokens, maxDepth, visitor, or Blob values before object serialization. The inherited options alter toFormData field naming and data interpretation, maxDepth can force request failure, Blob changes value handling, and a polluted visitor can execute when an attacker already has the stronger ability to inject a function. Serialized field naming and data interpretation can change, maxDepth can cause request failure, Blob can alter value handling, and a polluted visitor can execute under the stronger function-injection primitive. This issue is fixed in versions 0.34.0 and 1.20.0.