<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:08:35.348977+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-377770</id>
    <title>EUVD-2026-377770</title>
    <updated>2026-10-02T12:08:35.419232+00:00</updated>
    <content>EUVD-2026-377770</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-377770"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-101904</id>
    <title>fkie_cve-2026-101904</title>
    <updated>2026-10-02T12:08:35.419270+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes inherited Object.prototype.headers from a replacement request configuration. A separate same-process prototype-pollution flaw sets Object.prototype.headers, and trusted request interceptors return a new ordinary configuration without an own headers property. After the interceptor chain, dispatchRequest resolves the inherited headers during normalization. Downstream request processing can observe attacker-controlled headers, including authorization-related values. This issue is fixed in version 1.20.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-101904"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j8rh-479h-cp32</id>
    <title>GHSA-j8rh-479h-cp32 — Axios: Header Injection via Inherited headers After Minimal Interceptor</title>
    <updated>2026-10-02T12:08:35.419305+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: axios</p>
<p>## Summary</p>
<p>Axios request interceptors may return a replacement config object. If an interceptor returns a plain object without an own `headers` property, `dispatchRequest()` later evaluates `config.headers` and can resolve an inherited `Object.prototype.headers` value. In a process where another vulnerability has polluted `Object.prototype.headers`, axios can send attacker-controlled headers.</p>
<p>Axios does not create the prototype pollution source, and the interceptor itself is trusted caller code. The vulnerable behavior is the post-interceptor axios config read that reopens a prototype-pollution gadget after earlier null-prototype config hardening.</p>
<p>## Impact</p>
<p>An attacker with a prior same-process prototype-pollution primitive can inject headers into affected axios requests when the application uses an interceptor that rebuilds config and omits headers. Depending on the target service, injected headers can affect cache behavior, conditional requests, metadata services, or application-specific authorization and routing logic.</p>
<p>The issue is conditional and should not be described as affecting every interceptor or every request.</p>
<p>## Affected Functionality</p>
<p>Affected:</p>
<p>- Request interceptor chains where an interceptor returns a new ordinary object.
- Replacement config objects that omit an own `headers` property.
- `dispatchRequest()` header normalization through `AxiosHeaders.from(config.headers)`.</p>
<p>Not affected:</p>
<p>- Requests whose interceptor preserves an own `headers` property…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j8rh-479h-cp32"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-101904</id>
    <title>msrc_CVE-2026-101904 — Axios: Header Injection via Inherited headers After Minimal Interceptor</title>
    <updated>2026-10-02T12:08:35.419361+00:00</updated>
    <content>msrc_CVE-2026-101904</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-101904"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-101904</id>
    <title>UBUNTU-CVE-2026-101904</title>
    <updated>2026-10-02T12:08:35.419378+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:Pro:26.04:LTS: node-axios</p>
<p>Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes inherited Object.prototype.headers from a replacement request configuration. A separate same-process prototype-pollution flaw sets Object.prototype.headers, and trusted request interceptors return a new ordinary configuration without an own headers property. After the interceptor chain, dispatchRequest resolves the inherited headers during normalization. Downstream request processing can observe attacker-controlled headers, including authorization-related values. This issue is fixed in version 1.20.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-101904"/>
  </entry>
</feed>
