CVE Vulnerabilities

CVE-2026-101902

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Published: Sep 28, 2026 | Modified: Sep 30, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If another vulnerability in the same process pollutes Object.prototype.method, calls such as axios.request({ url }) and axios({ url }) can send a state-changing HTTP method instead of the expected default GET. Axios does not create the prototype pollution source. This is a read-side gadget in axios request dispatch. This issue is fixed in version 0.34.0 and 1.20.0.

Weakness

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Hardened ImagesRedHatgrafana13-1-main-13.1.6-0.6.hum1*
Red Hat Hardened ImagesRedHatgrafana12-4-main-12.4.12-0.3.hum1*
Red Hat Hardened ImagesRedHatgrafana13-2-main-13.2.1-0.9.hum1*
Node-axiosUbuntuupstream*

Potential Mitigations

References