AXIOS has released patches addressing ten security vulnerabilities in its Node[.]js HTTP adapter, including prototype pollution and denial-of-service risks. The issues affect Axios up to version 1.19.x, spanning the 0.x and 1.x release lines, with the highest-severity flaw rated CVSSv4 8.3 (CVE-2026-101909). Owners should upgrade to version 1.20.0 immediately, with 0.34.0 also offering fixes for older branches. The article notes that there is no confirmed exploitation in the wild, but emphasises the urgency of updating given Axios’ widespread use.
The vulnerabilities encompass a mix of prototype-pollution gadgets and ReDoS weaknesses across various adapters, including the toFormData and fetch adapters, as well as issues in the HTTP/2 client and header handling.
Notable CVEs highlighted include CVE-2026-101909 (Prototype Pollution Gadget in toFormData Options), CVE-2026-101906 (ReDoS in shouldBypassProxy host normalization), CVE-2026-101903 (ReDoS in fromDataURI data: URL parser), CVE-2026-101901 (Unhandled 'error' in HTTP/2 ClientHttp2Session Initialization), and several others describing SSRF risks and header manipulation. Researchers have published proof-of-concept demonstrations, though there is no established evidence of active exploitation at the time of reporting.
Mitigation guidance is clear: upgrade Axios to 1.20.0 to remediate the flaws, consider also updating to 0.34.0 for older branches, and avoid passing untrusted data to request options. Disabling HTTP/2 for untrusted destinations and reviewing official Axios advisories are additional prudent steps while organisations deploy the patch. The article stresses that, given Axios’ popularity, millions of applications could be affected if left unpatched. Published 1 October 2026.