CVE-2026-101908 Axios 原型污染请求头覆盖漏洞
影响攻击者可注入任意请求头,篡改认证与缓存等行为
Axios 的 fetch 适配器在构造 Request 时使用了经过清理的 resolvedOptions,但实际调用 fetch 时却传入了原始的 fetchOptions。当同进程存在原型污染漏洞时,Object.prototype.headers 会被污染,fetchOptions.headers 通过原型链继承到攻击者可控的值,从而覆盖已清理的请求头。该问题在 1.20.0 版本中修复。
影响范围
Axios 1.7.0 至 1.20.0 之前的版本,涉及使用 fetch 适配器的场景。
漏洞详情
这是一个请求头注入类漏洞。fetch 适配器先用清理后的配置构造 Request 对象,但随后调用 fetch 时又传入了未清理的原始 fetchOptions,第二个参数中的 headers 会覆盖 Request 中已清理的请求头。攻击者需先利用同进程中的另一个原型污染漏洞,将恶意请求头写入 Object.prototype.headers,即可借由原型链继承注入任意请求头。
利用条件与风险
利用前提是目标进程已存在可被利用的原型污染漏洞,属于组合利用条件。一旦满足,攻击者可篡改 Authorization、缓存、元数据服务访问等请求头,实战风险较高。
修复建议
升级至 Axios 1.20.0 或更高版本。临时缓解措施包括排查并修复同进程中的原型污染漏洞,避免不可信输入进入对象合并逻辑。
Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but then calls fetch with the original fetchOptions. A separate same-process prototype-pollution flaw populates Object.prototype.headers so fetchOptions.headers resolves through inheritance. The inherited fetchOptions.headers value overrides the sanitized Request headers through the second argument to fetch after Request construction. Attacker-controlled request headers can alter authorization, caching, metadata-service access, or application-specific behavior. This issue is fixed in version 1.20.0.