AI analysis
Axios 1.16.1 before 1.20.0 uses an inefficient regular expression (CWE-1333) when parsing RFC 2397 data URLs in fromDataURI and DATA_URL_PATTERN. The pattern allows slash characters on both sides of the media-type separator, so a malformed data URL with many slashes and no comma forces the JavaScript engine to try many separator placements before rejecting the input. That synchronous backtracking can block the Node.js event loop and cause a denial of service; CVSS rates availability high and confidentiality and integrity unaffected, and the attack only works if the application passes attacker-controlled data URLs into this parser. Both browser and Node.js users of those Axios releases are in scope where untrusted data URLs are processed. The issue is fixed in 1.20.0, is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Upgrade Axios to 1.20.0 or later and refresh lockfiles so direct and transitive dependencies resolve to the fixed release. Until then, do not pass untrusted or attacker-controlled data URLs into Axios data-URI handling (fromDataURI / DATA_URL_PATTERN). Confirm what is installed with npm ls axios or the equivalent for your package manager.
Affected
| Axios | 1.16.1 up to, but not including, 1.20.0 |
Estimated exposure
largeOn the order of hundreds of thousands to low millions of projects may have resolved a vulnerable Axios release while 1.16.x–1.19.x were current (exact count… — Axios is one of the most widely used JavaScript HTTP clients, with tens of millions of weekly npm downloads and heavy transitive use, but only the narrow 1.16.1–pre-1.20.0 window is affected and only apps that feed it untrusted data URLs…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash characters on both sides of the media-type separator. An application passes an attacker-controlled malformed data URL containing many slash characters and no comma. the JavaScript regular-expression engine explores many separator placements before rejecting the URL. Synchronous excessive backtracking can block the Node.js event loop and cause denial of service. The affected identifiers are fromDataURI, DATA_URL_PATTERN, data:. This issue is fixed in version 1.20.0.