← All CVEs NewScan detects
medium

CVE-2026-101902

axios 0.x before 0.34.0: a default-instance request that omits an explicit method reads an inherited method from a polluted prototype, and toFormData processes inherited serialization options

Severity
medium
Affected product
axios
Affected versions
axios ≥ 0.27.2, < 0.34.0
Fixed in
axios 0.34.0
Detection basis
Component version range
Shipped rule
axios: axios 0.x before 0.34.0: a default-instance request that omits an explicit method reads an inherited method from a polluted prototype, and toFormData processes inherited serialization options
Added to NewScan
2026-09-29
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints axios from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-29 (/daily-cve) alongside the 1.x row above. A SEPARATE row rather than a widened range, on the Bouncy Castle LTS precedent already in version_tools._aliases: axios 0.x is its own maintained series with its own fix release (npm dist-tag `v0x` reads 0.34.0, verified against registry.npmjs.org on 2026-09-29, the same read that confirmed `latest` is 1.20.0), so a single `lt: 1.20.0` with no floor would flag a patched 0.34.0 as vulnerable - a false positive on every up-to-date 0.x install, which is the one thing a version gate must not do. The two ids are the 0.x arms of advisories whose 1.x arms are on the row above; both are genuinely in range across the whole span except that 101909 starts at 0.28.0, so it is in `cves` and 101902 (0.27.2 and up) is the version-matched id. `medium` not high: the 0.x line has no HTTP/2 adapter and no fetch adapter, so neither of the two SSRF-shaped ids from the 1.x batch exists here - what is left is prototype pollution reached through an attacker-influenced config or form payload. Same version source as the row above (mined /package.json, /package-lock.json, /yarn.lock through the `axios` key that already exists in this pack); version-match only.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →

Review the measured benchmark, then use the verified remediation process.