🛡️ CVE Monitor
Dịch vụ / phần mềm liên quan: Node.js / npm
⚠️ NVD chưa công bố điểm CVSS cho CVE này (thường do CVE vừa công bố, đang chờ NVD phân tích) — mức độ sẽ tự cập nhật ở lần đồng bộ sau.

Mô tả

Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormData headers. A separate same-process prototype-pollution flaw supplies an array or non-plain class instance whose inherited properties make it appear FormData-like; plain objects are blocked. The inherited getHeaders function can return attacker-controlled headers that resolveConfig merges into a fetch adapter request. Attacker-controlled headers can alter authorization, cache, metadata-service, or application-specific request behavior. This issue is fixed in version 1.20.0.

Chi tiết

Trạng tháiReceived
Điểm CVSS0.0 (v)
Vector CVSS
Ngày công bố01:17 29/09/2026
Ngày cập nhật01:17 29/09/2026
Nguồn dữ liệunvd

CWE

  • CWE-74
  • CWE-693
  • CWE-1321

Sản phẩm bị ảnh hưởng

Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.

Tài liệu tham khảo

Lịch sử thay đổi

Thời gianLoạiTrườngGiá trị cũGiá trị mới
01:17 29/09/2026 CREATED cve UNKNOWN

Tất cả thời gian trên trang này hiển thị theo giờ Việt Nam (GMT+7).