Axios request interceptors may return a replacement config object. If an interceptor returns a plain object without an own headers property, dispatchRequest() later evaluates config.headers and can resolve an inherited Object.prototype.headers value. In a process where another vulnerability has polluted Object.prototype.headers, axios can send attacker-controlled headers.
Axios does not create the prototype pollution source, and the interceptor itself is trusted caller code. The vulnerable behavior is the post-interceptor axios config read that reopens a prototype-pollution gadget after earlier null-prototype config hardening.
An attacker with a prior same-process prototype-pollution primitive can inject headers into affected axios requests when the application uses an interceptor that rebuilds config and omits headers. Depending on the target service, injected headers can affect cache behavior, conditional requests, metadata services, or application-specific authorization and routing logic.
The issue is conditional and should not be described as affecting every interceptor or every request.
Affected:
headers property.dispatchRequest() header normalization through AxiosHeaders.from(config.headers).Not affected:
headers property.lib/core/dispatchRequest.js contains:
config.headers = AxiosHeaders.from(config.headers);
The initial merged config is null-prototype, but an interceptor can replace it with a normal object. If that object has no own headers, the read can resolve Object.prototype.headers.
Local verification on axios 1.18.1 polluted Object.prototype.headers = { 'X-Poisoned': 'yes' }, installed an interceptor that returned { url, method, timeout, proxy: false }, and sent a request. The loopback server received X-Poisoned: yes.
Constrained local demonstration:
Object.prototype.headers = { 'X-Poisoned': 'yes' };
const client = axios.create();
client.interceptors.request.use((config) => ({
url: config.url,
method: config.method,
timeout: config.timeout
}));
await client.get(url);
Expected safe behavior is that missing headers normalize to an empty header set. Current affected behavior reads inherited Object.prototype.headers.
Interceptors that rebuild config should always set an own headers property, for example by preserving config.headers or setting headers: {}. Mutating and returning the existing merged config also avoids replacing the null-prototype object.
Axios 1.17.0 blocks the old Object.prototype.common header bucket gadget. However, if a request interceptor rebuilds a minimal config object and omits headers, dispatchRequest() reads inherited Object.prototype.headers.
This allows attacker-controlled headers to be placed on the wire.
Validated on:
1.17.04306df2v24.15.0Object.prototype.headers.headers.dispatchRequest() uses:
config.headers = AxiosHeaders.from(config.headers);
If config is a normal object returned by an interceptor and lacks own headers, this reads Object.prototype.headers.
An attacker can inject request headers. Depending on the target service, this can cause cache manipulation, conditional-response suppression, request smuggling preconditions, metadata-service header injection, or application-specific authorization bypass.
import axios from './index.js';
import http from 'http';
const start = (handler) => new Promise((resolve) => {
const server = http.createServer(handler);
server.listen(0, '127.0.0.1', () => resolve(server));
});
const stop = (server) => new Promise((resolve) => server.close(resolve));
const hits = [];
const server = await start((req, res) => {
hits.push(req.headers);
res.setHeader('Content-Type', 'application/json');
res.end('{"ok":true}');
});
try {
Object.prototype.headers = {
'X-Poisoned': 'yes',
'If-None-Match': '*'
};
const client = axios.create();
client.interceptors.request.use((config) => ({
url: config.url,
method: config.method,
timeout: config.timeout
}));
await client.get(`http://127.0.0.1:${server.address().port}/headers`, {
timeout: 3000
});
console.log(hits[0]);
} finally {
delete Object.prototype.headers;
await stop(server);
}
Observed wire headers:
{
"x-poisoned": "yes",
"if-none-match": "*",
"user-agent": "axios/1.17.0"
}
{
"cwe_ids": [
"CWE-1321",
"CWE-74"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-30T15:35:14Z",
"nvd_published_at": "2026-09-28T18:17:18Z",
"severity": "MODERATE"
}