CVE-2026-101909
- EPSS 0.35%
- Veröffentlicht 28.09.2026 17:42:40
- Zuletzt bearbeitet 01.10.2026 15:17:24
Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution. A separate same-proc...
CVE-2026-101908
- EPSS 0.41%
- Veröffentlicht 28.09.2026 17:38:55
- Zuletzt bearbeitet 30.09.2026 19:38:27
Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but then calls fetch with the original fetchOptions. A separate same-process prototype-po...
- EPSS 0.41%
- Veröffentlicht 28.09.2026 17:36:03
- Zuletzt bearbeitet 30.09.2026 19:38:27
Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter with maxRedirects set to zero and receives a redirect ...
CVE-2026-101906
- EPSS 0.4%
- Veröffentlicht 28.09.2026 17:32:40
- Zuletzt bearbeitet 30.09.2026 19:38:27
Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.0 until 1.20.0, Axios shouldBypassProxy applies a quadratic trailing-dot regular expression to redirect hostnames. HTTP_PROXY or HTTPS_PROXY is configured, NO_PROXY or no_pro...
CVE-2026-101905
- EPSS 0.29%
- Veröffentlicht 28.09.2026 17:31:00
- Zuletzt bearbeitet 01.10.2026 15:17:24
Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process prototype-pollution flaw...
CVE-2026-101904
- EPSS 0.43%
- Veröffentlicht 28.09.2026 17:29:10
- Zuletzt bearbeitet 30.09.2026 19:38:27
Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes inherited Object.prototype.headers from a replacement request configuration. A separate same-process prototype-pollutio...
CVE-2026-101903
- EPSS 0.38%
- Veröffentlicht 28.09.2026 17:25:04
- Zuletzt bearbeitet 30.09.2026 19:38:27
Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash characters on both sides of the media-type separator. An application passes an attacker-controlled malformed data...
CVE-2026-101902
- EPSS 0.41%
- Veröffentlicht 28.09.2026 17:22:49
- Zuletzt bearbeitet 30.09.2026 19:38:27
Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If another vulnerability in ...
CVE-2026-101901
- EPSS 0.38%
- Veröffentlicht 28.09.2026 17:16:21
- Zuletzt bearbeitet 01.10.2026 15:17:24
Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse. A request uses httpVersio...
CVE-2026-101900
- EPSS 0.55%
- Veröffentlicht 28.09.2026 17:14:07
- Zuletzt bearbeitet 30.09.2026 19:38:27
Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormData headers. A separate same-process prototype-pollut...