Axios HTTP/2 Flaws Enable SSRF Control Bypass and Node.js Denial of Service
Axios HTTP/2 bugs CVE-2026-101898 and CVE-2026-101901 allow SSRF-control bypass and Node.js denial of service.
Axios disclosed two high-severity HTTP/2 flaws affecting versions 1.13.0 through 1.19.x, both fixed in 1.20.0. CVE-2026-101898 can ignore caller-supplied DNS lookup policies and proxy settings, so applications that fetch user-controlled URLs with httpVersion 2 may connect directly and bypass SSRF protections. CVE-2026-101901 fails to handle ClientHttp2Session errors, allowing an error event to become an uncaught Node.js exception and terminate the process. No exploitation in the wild is reported; operators should upgrade or disable HTTP/2 and keep egress filtering outside the application.
- CVE-2026-101898 can bypass custom DNS lookup and proxy controls on HTTP/2.
- CVE-2026-101901 can crash Node.js through an unhandled HTTP/2 session error.
- Axios 1.13.0 through 1.19.x are affected; both flaws are fixed in 1.20.0.
- Risk is highest when applications fetch attacker-controlled URLs with HTTP/2.
Vulnerabilities mentionedAll →
- CVE-2026-1019018.2—Unhandled HTTP/2 session error DoS in Axiospublished · axios+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-101901+1 related CVE | Unhandled HTTP/2 session error DoS in Axios Axios, a promise-based HTTP client for the browser and Node.js, fails to attach adequate error handling to a ClientHttp2Session when an HTTP/2 session is created or reused. From version 1.13.0 until the fix in 1.20.0, a request that sets httpVersion to 2 can cause the session to emit an error that is not turned into a normal Promise rejection. That uncaught error can crash the Node.js process and deny service to the application. Only Node.js callers that use Axios HTTP/2 on those versions are affected; browser use of Axios is outside this flaw. There is no known public proof of concept and no report of exploitation in the wild. |
Full article470 words · extracted from cybersecuritynews.com · click to collapse
Axios has disclosed two high-severity vulnerabilities in its HTTP/2 implementation that could allow attackers to bypass outbound network controls or crash vulnerable Node.js applications. The flaws affect Axios versions 1.13.0 through 1.19.x and have been fixed in version 1.20.0
The first issue, tracked as GHSA-3pq3-5fj3-cg6v and CVE-2026-101898, affects Axios applications that use HTTP/2 requests alongside custom DNS lookup functions or proxy settings.
Axios may fail to apply caller-supplied config. It may fail to apply caller-supplied DNS lookup policies, explicit proxy settings, or proxy configuration inherited from environment variables before creating an HTTP/2 connection.
This creates a server-side request forgery risk in applications that accept user-controlled URLs. Security teams commonly use a custom DNS resolver to block internal addresses, cloud metadata services, localhost targets, or private network ranges.
Other deployments force outbound traffic through an inspection proxy. Under the vulnerable HTTP/2 code path, Axios can connect directly to a destination instead of honoring those protections.
Axios HTTP/2 Flaws
An attacker could abuse the flaw when an application passes a user-influenced destination into Axios with httpVersion: 2. For example, a web service designed to fetch external URLs may use a DNS allowlist to prevent requests to 127.0.0.1, RFC1918 networks, or cloud metadata endpoints.
If the service switches to the affected HTTP/2 adapter, Axios could bypass the custom lookup or proxy route and send a direct request to a restricted resource.
The second issue, GHSA-542g-h47m-68v8 and CVE-2026-101901, can cause denial-of-service in Node.js applications. Axios did not install adequate error handling for a ClientHttp2Session during HTTP/2 session initialization or reuse.
If that session emits an error event, the event may escape Axios’s normal Promise rejection handling and become an uncaught exception.
In Node.js, an unhandled error event can terminate the running process. Therefore, an attacker who can influence a request flow that creates or reuses an Axios HTTP/2 session may be able to force an affected service offline.
The practical risk is highest in applications that use Axios to retrieve attacker-controlled URLs, call external integrations, process webhooks, or proxy requests to user-specified hosts.
The Axios advisory covers two high-severity flaws following the introduction of HTTP/2 support in its Node.js HTTP adapter in version 1.13.0.
Organizations should upgrade Axios to version 1.20.0 or later immediately. Until patching is complete, teams should turn off HTTP/2 requests by removing httpVersion: 2 or using HTTP/1.1.
Defenders should also review applications that fetch user-supplied URLs, validate destination hosts before initiating requests, maintain egress filtering outside the application layer, and monitor outbound connections for unexpected internal or metadata-service access.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.