CVE Vulnerabilities

CVE-2026-101900

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Published: Sep 28, 2026 | Modified: Sep 30, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormData headers. A separate same-process prototype-pollution flaw supplies an array or non-plain class instance whose inherited properties make it appear FormData-like; plain objects are blocked. The inherited getHeaders function can return attacker-controlled headers that resolveConfig merges into a fetch adapter request. Attacker-controlled headers can alter authorization, cache, metadata-service, or application-specific request behavior. This issue is fixed in version 1.20.0.

Weakness

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Hardened ImagesRedHatgrafana13-1-main-13.1.6-0.6.hum1*
Red Hat Hardened ImagesRedHatgrafana12-4-main-12.4.12-0.3.hum1*
Red Hat Hardened ImagesRedHatgrafana13-2-main-13.2.1-0.9.hum1*
Node-axiosUbuntuupstream*

Potential Mitigations

References