CVE-2026-101904

CVE-2026-101904 published: Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes inherited Object.prototype.headers from a replacement request configuration. A separate same-process prototype-pollution flaw ...

View full NVD advisory → ← Back to CVE watch