Axios Flaws Let Attackers Bypass Proxy Controls and Trigger SSRF Attacks
Axios disclosed seven high-severity flaws, including HTTP/2 SSRF proxy bypass; attackers could reach internal services and cloud metadata; patched in 1.20.0.
Axios maintainers disclosed multiple high-severity vulnerabilities, led by GHSA-3pq3-5fj3-cg6v (CVE-2026-101898), where the HTTP/2 adapter ignores custom DNS lookup handlers, agents, and proxy settings, bypassing SSRF defenses. A related advisory (GHSA-44g4-m2mj-wpvx) notes Axios ignores CIDR-form NO_PROXY entries used to exclude private subnets like 10.0.0.0/8. Additional high-severity issues include prototype pollution in toFormData, ReDoS in two components, a fetch adapter ignoring maxRedirects, and mishandling of 0.0.0.0 and loopback variants in NO_PROXY checks.
- HTTP/2 path bypasses proxy and custom DNS controls, enabling direct SSRF connections
- NO_PROXY CIDR entries ignored, undermining private-subnet exclusion policies
- Seven CVEs rated high; HTTP/2 flaw affects versions 1.13.0 through 1.20.0, fixed in 1.20.0
- Inventory Node.js apps where users influence outbound URLs or fetch webhooks/remote content
Vulnerabilities mentionedAll →
- CVE-2026-1019098.3—Prototype pollution in Axios toFormData optionspublished · Axios+6 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-101909 |
Full article607 words · extracted from gbhackers.com · click to collapse
Axios maintainers have disclosed several high-severity security vulnerabilities that could allow attackers to bypass proxy and DNS controls in server-side applications, potentially enabling server-side request forgery (SSRF) against internal services and cloud metadata endpoints.
The most critical issue, tracked as GHSA-3pq3-5fj3-cg6v, affects Axios’s HTTP/2 request path. This vulnerability arises because the HTTP/2 adapter establishes sessions through `http2.connect()` using only `options.http2Options`, neglecting top-level Axios settings such as custom DNS lookup handlers, agents, and proxy configuration.
As a result, requests developers expect to monitor, route, or block via a proxy can instead connect directly to their intended destination.
Axios Flaws
This issue is particularly dangerous for applications that let users influence outbound URLs, enable Axios HTTP/2 support, and rely on proxies or custom DNS resolvers to safeguard against SSRF. An attacker could supply a URL targeting an internal hostname, private IP address, or cloud metadata service.
If the application’s defenses depend on Axios proxy routing or a custom lookup function to reject sensitive destinations, the HTTP/2 execution path may bypass these controls and establish a direct connection.
Axios’s advisory indicates that the vulnerability affects server-side deployments where Axios is used as an outbound HTTP client and network controls are enforced at the library configuration layer.
Successful exploitation could expose internal API responses, cloud-instance metadata, credentials, or administrative interfaces. It could also permit state-changing requests to services that are otherwise intended to remain inaccessible.
The HTTP/2 issue affects Axios versions 1.13.0 through 1.20.0 and has been fixed in version 1.20.0, according to vulnerability tracking data.
The HTTP/2 flaw was disclosed alongside several proxy-handling issues in Axios that can weaken SSRF defenses based on HTTP_PROXY, HTTPS_PROXY, and NO_PROXY environment variables.
One related advisory, GHSA-44g4-m2mj-wpvx, states that Axios ignores CIDR-form entries in NO_PROXY. Organizations commonly use CIDR entries to prevent proxying traffic for private subnets, such as 10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16. Axios’s failure to recognize these exclusions can undermine proxy-routing policies and defense-in-depth strategies.
CVE Details
| CVE ID | Vulnerability | Severity | Affected Versions |
|---|---|---|---|
| CVE-2026-101901 | Unhandled error event in HTTP/2 ClientHttp2Session initialization | High | >= 1.13.0 |
| CVE-2026-101898 | HTTP/2 adapter bypasses custom DNS lookup and proxy controls | High | >= 1.13.0 |
| CVE-2026-101909 | Prototype-pollution gadget in toFormData options | High | >= 0.28.0; >= 1.15.1 |
| CVE-2026-101906 | ReDoS in shouldBypassProxy hostname normalization | High | Not specified in supplied advisory data |
| CVE-2026-101903 | ReDoS in fromDataURI data: URL parser | High | >= 1.16.1 |
| CVE-2026-101907 | Fetch adapter ignores maxRedirects: 0 | High | 1.17.0 |
| CVE-2026-101905 | Axios proxy/intermediary issue | High | Not specified in supplied advisory data |
Earlier flaws in Axios also involved hostname normalization and edge cases concerning IP addresses. For example, malformed or alternate representations of loopback destinations, such as `localhost.` or bracketed IPv6 literals, could evade literal NO_PROXY comparisons and force traffic through a configured proxy.
Another issue affects how the address 0.0.0.0 is handled. Axios versions 1.15.0 through 1.16.1 reportedly failed to treat this address as local when evaluating NO_PROXY policy.
An attacker who can control a request URL could use a 0.0.0.0 target to redirect requests unexpectedly, potentially exposing local services through a proxy that can relay the traffic.
Security teams should immediately inventory Node.js applications that use Axios for outbound requests, particularly those that fetch user-supplied URLs, process webhooks, render remote content, or integrate with cloud services.
The disclosures highlight a recurring risk in outbound request security: proxy settings and URL validation must be consistently applied across all protocol adapters, redirect paths, DNS resolution flows, and address representations.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.