
🟠 Axios, Prototype Pollution Gadget, #CVE-2026-101902 (Medium) -DC-Sep2026-2666 https://dailycve.com/axios-prototype-pollution-gadget-cve-2026-101902-medium-dc-sep2026-2666/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If another vulnerability in the same process pollutes Object.prototype.method, calls such as axios.request({ url }) and axios({ url }) can send a state-changing HTTP method instead of the expected default GET. Axios does not create the prototype pollution source. This is a read-side gadget in axios request dispatch. This issue is fixed in version 0.34.0 and 1.20.0.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🟠 Axios, Prototype Pollution Gadget, #CVE-2026-101902 (Medium) -DC-Sep2026-2666 https://dailycve.com/axios-prototype-pollution-gadget-cve-2026-101902-medium-dc-sep2026-2666/