CVE-2026-101905

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process prototype-pollution flaw places a function on Object.prototype.createConnection. Node resolves and invokes the inherited createConnection socket factory, allowing the attacker-controlled function to select the transport endpoint. The attacker endpoint can receive request headers and bodies, including credentials, and return attacker-controlled responses while the URL appears legitimate. This issue is fixed in version 1.20.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-441CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-09-30); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-09-30: 1Mentions · 2026-10-01: 109-3010-01
Referenced assets1 URL
Full discourse2 posts
  • JFrog Security@JFrogSecurity

    🚨 New High-severity Axios CVEs: Same story, different numbers. Axios recently released CVE-2026-101905 & CVE-2026-101909 as High severity. 🚩 The catch? Just like previous Axios flaws, they are impossible to exploit on their own and require a pre-existing Prototype Pollution vulnerability in your application. 💡 JFrog Severity: Medium. While the impact is high, exploitation strictly depends on a completely separate vulnerability outside of Axios. These new CVEs follow the exact same pattern of severity inflation we broke down in our recent research:

    0301262.0K
    5.6K followersView on X
  • DailyCVE@dailycve

    🔴 Nodejs HTTP Adapter, Prototype Pollution Gadget, #CVE-2026-101905 (High) -DC-Sep2026-2670 https://dailycve.com/nodejs-http-adapter-prototype-pollution-gadget-cve-2026-101905-high-dc-sep2026-2670/

    0001032
    238 followersView on X

Explore more