Prototype Pollution Vulnerability in Axios Request Interceptors
Article Content
- •Axios request interceptors can be exploited for prototype pollution.
- •Attackers can inject headers into requests if interceptors omit their own headers property.
- •The vulnerability is conditional and does not affect all requests or interceptors.
A vulnerability in Axios request interceptors allows for prototype pollution, potentially enabling attackers to inject malicious headers into requests. If an interceptor returns a plain object without its own headers property, the dispatchRequest function may read from the inherited Object.prototype.headers. This issue arises when a prior prototype pollution primitive is present in the same process. The vulnerability affects Axios versions where interceptors can return a new ordinary object without headers. The problem is conditional, not affecting all interceptors or requests. Affected functionality includes request interceptor chains that return new ordinary objects and replacement config objects that lack an own headers property. The issue was verified locally on Axios version 1.18.1. Users are advised to ensure interceptors set their own headers property to mitigate this risk.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
Which Axios versions are affected?
How can I mitigate this vulnerability?
Is there a patch available?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…