Bug 2542592 (CVE-2026-101908)
| Summary: | CVE-2026-101908 axios: Axios: Outbound HTTP request manipulation via fetch adapter prototype pollution | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Axios. When using the fetch adapter, Axios fails to properly isolate request configuration options from inherited object properties. If an attacker first exploits a separate prototype pollution vulnerability (where shared JavaScript object properties are modified) within the application, the fetch adapter can inherit those manipulated headers into outbound network calls. This allows an attacker to alter outgoing requests, potentially bypassing authorization controls, corrupting cache behavior, or accessing restricted internal services.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-28 17:57:44 UTC
|