CVE-2026-101902
axios 0.x before 0.34.0: a default-instance request that omits an explicit method reads an inherited method from a polluted prototype, and toFormData processes inherited serialization options
- Severity
- medium
- Affected product
- axios
- Affected versions
- axios ≥ 0.27.2, < 0.34.0
- Fixed in
- axios 0.34.0
- Detection basis
- Component version range
- Shipped rule
- axios: axios 0.x before 0.34.0: a default-instance request that omits an explicit method reads an inherited method from a polluted prototype, and toFormData processes inherited serialization options
- Added to NewScan
- 2026-09-29
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints axios from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-29 (/daily-cve) alongside the 1.x row above. A SEPARATE row rather than a widened range, on the Bouncy Castle LTS precedent already in version_tools._aliases: axios 0.x is its own maintained series with its own fix release (npm dist-tag `v0x` reads 0.34.0, verified against registry.npmjs.org on 2026-09-29, the same read that confirmed `latest` is 1.20.0), so a single `lt: 1.20.0` with no floor would flag a patched 0.34.0 as vulnerable - a false positive on every up-to-date 0.x install, which is the one thing a version gate must not do. The two ids are the 0.x arms of advisories whose 1.x arms are on the row above; both are genuinely in range across the whole span except that 101909 starts at 0.28.0, so it is in `cves` and 101902 (0.27.2 and up) is the version-matched id. `medium` not high: the 0.x line has no HTTP/2 adapter and no fetch adapter, so neither of the two SSRF-shaped ids from the 1.x batch exists here - what is left is prototype pollution reached through an attacker-influenced config or form payload. Same version source as the row above (mined /package.json, /package-lock.json, /yarn.lock through the `axios` key that already exists in this pack); version-match only.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →Review the measured benchmark, then use the verified remediation process.