AI analysis
Axios, a promise-based HTTP client for the browser and Node.js, fails to attach adequate error handling to a ClientHttp2Session when an HTTP/2 session is created or reused. From version 1.13.0 until the fix in 1.20.0, a request that sets httpVersion to 2 can cause the session to emit an error that is not turned into a normal Promise rejection. That uncaught error can crash the Node.js process and deny service to the application. Only Node.js callers that use Axios HTTP/2 on those versions are affected; browser use of Axios is outside this flaw. There is no known public proof of concept and no report of exploitation in the wild.
What to do: Upgrade Axios to 1.20.0 or later in every Node.js service that can set httpVersion to 2. Until then, do not use the HTTP/2 client path, and check lockfiles and transitive dependencies for axios versions from 1.13.0 up to but not including 1.20.0.
Affected
| axios | 1.13.0 through versions before 1.20.0 |
Estimated exposure
largeon the order of 100,000–1,000,000+ Node.js deployments plausibly on a vulnerable release, with a smaller subset using HTTP/2 — Axios is one of the most widely used npm HTTP clients (tens of millions of weekly downloads and a very large dependent-project base); only Node.js apps on 1.13.0–pre-1.20.0 that opt into HTTP/2 are actually vulnerable, so the exposed set…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse. A request uses httpVersion: 2 and the ClientHttp2Session emits an error during session initialization or reuse. The unhandled session error escapes normal Promise rejection handling. The uncaught error can terminate the Node.js process and cause denial of service. This issue is fixed in version 1.20.0.