{"id":"AZL-105245","summary":"CVE-2026-101902 affecting package python-tensorboard 2.16.2-6","details":"Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If another vulnerability in the same process pollutes Object.prototype.method, calls such as axios.request({ url }) and axios({ url }) can send a state-changing HTTP method instead of the expected default GET. Axios does not create the prototype pollution source. This is a read-side gadget in axios request dispatch. This issue is fixed in version 0.34.0 and 1.20.0.","modified":"2026-10-03T05:35:10Z","published":"2026-09-28T18:17:18Z","upstream":["CVE-2026-101902"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101902"}],"affected":[{"package":{"name":"python-tensorboard","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/python-tensorboard"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.16.2-6"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105245.json"}}],"schema_version":"1.9.0"}