Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.8 React GHSA-542g-h47m-68v8 CVE-2026-101901 GHSA-mghh-pgcx-3jjj CVE-2026-101906

Axios 1.20.0 Fixes Eight Vulnerabilities: DoS, SSRF, and Prototype-Pollution Gadgets

Axios, a widely used HTTP client for Node.js and browsers, has patched eight separate vulnerabilities in version 1.20.0, including denial-of-service issues, SSRF-style proxy/DNS bypasses, a redirect-policy bypass, and several prototype-pollution gadgets affecting the fetch adapter and default request dispatch.

AI summary

Axios, the promise-based HTTP client used extensively in Node.js and browser applications, has received version 1.20.0, which addresses eight distinct, separately identified vulnerabilities. These range from denial-of-service conditions triggered by unhandled HTTP/2 session errors and inefficient regular expressions, to bypasses of configured proxy and DNS lookup behavior, a redirect-policy bypass in the fetch adapter, and several gadget-style issues where a pre-existing prototype-pollution flaw elsewhere in an application could be leveraged through Axios's request-handling code. None of these issues are reported as actively exploited, and no public exploit code has been noted in the fact package. All eight are resolved in axios 1.20.0.

What happened

GitHub Advisory Database and NVD published eight separate advisories for axios on 2026-09-28/30, all affecting versions prior to 1.20.0 and all fixed in that release: - CVE-2026-101901 (GHSA-542g-h47m-68v8): Missing error handling for a ClientHttp2Session during HTTP/2 session initialization or reuse can let an uncaught session error crash the Node.js process (denial of service). - CVE-2026-101906 (GHSA-mghh-pgcx-3jjj): The shouldBypassProxy hostname-normalization logic uses a regular expression vulnerable to quadratic backtracking, reachable via a crafted redirect Location header when a proxy and NO_PROXY/no_proxy are configured and redirects are followed. - CVE-2026-101903 (GHSA-c29m-xwm3-cm6r): The RFC 2397 data-URL parsing regular expression (fromDataURI / DATA_URL_PATTERN) permits excessive backtracking when processing a malformed data: URL containing many slash characters and no comma, blocking the event loop. - CVE-2026-101907 (GHSA-r4gj-5m52-g5wh): The fetch adapter does not enforce maxRedirects: 0; the underlying fetch implementation follows redirects anyway, potentially exposing internal responses or state-changing internal endpoints. - CVE-2026-101898 (GHSA-3pq3-5fj3-cg6v): HTTP/2 request setup does not consistently apply configured proxy settings or a caller-supplied DNS lookup policy, allowing requests to bypass intended proxy routing or DNS resolution controls. - CVE-2026-101902 (GHSA-9fr6-4gfg-395g): Default-instance requests that omit an explicit HTTP method can read an inherited Object.prototype.method value; if another vulnerability in the same process has polluted Object.prototype, this can cause axios to send an unexpected state-changing method instead of the default GET. - CVE-2026-101900 (GHSA-4hqw-qxg8-jxx2): resolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties when resolving FormData headers; combined with a separate prototype-pollution flaw, this can let attacker-controlled headers be merged into a fetch-adapter request. - CVE-2026-101908 (GHSA-vh66-26gq-q6x8): The fetch adapter builds a sanitized Request object but then calls fetch with the original, unsanitized fetchOptions; combined with a separate prototype-pollution flaw populating Object.prototype.headers, inherited header values can override the sanitized request headers.

Technical root causes

The eight issues fall into distinct categories. Three are denial-of-service/resource-exhaustion problems (CWE-400, CWE-1333): an unhandled 'error' event on an HTTP/2 ClientHttp2Session, and two separately vulnerable regular expressions (in proxy-bypass hostname normalization and in data-URL parsing) that exhibit quadratic or excessive backtracking on attacker-influenced input, blocking Node.js's single-threaded event loop. Two issues (CWE-918, CWE-441) involve routing controls not being honored: the HTTP/2 code path can skip configured proxy and DNS-lookup settings, and the fetch adapter can follow redirects even when maxRedirects is explicitly set to 0. The remaining three issues (CWE-1321, CWE-74) are 'gadget' vulnerabilities: axios itself does not introduce prototype pollution, but if an application already has a separate prototype-pollution flaw elsewhere, axios's request-dispatch and fetch-adapter code can read inherited properties (method, getHeaders, headers) from Object.prototype and use attacker-influenced values when constructing outbound requests.

Why it matters

Axios is one of the most widely used HTTP client libraries in the JavaScript ecosystem, used in both server-side Node.js applications and browser code. The denial-of-service issues (CVE-2026-101901, CVE-2026-101906, CVE-2026-101903) can be triggered remotely without authentication or user interaction in applications that process attacker-influenced HTTP/2 sessions, redirect targets, or data: URLs, and could crash or hang a Node.js process. The proxy/DNS and redirect-policy bypasses (CVE-2026-101898, CVE-2026-101907) undermine network-layer controls that applications may rely on to prevent SSRF or to isolate internal services. The prototype-pollution gadgets (CVE-2026-101902, CVE-2026-101900, CVE-2026-101908) are not exploitable by axios alone, but they increase the impact of any existing prototype-pollution vulnerability elsewhere in an application's dependency chain, turning a pollution bug into a mechanism for sending unexpected HTTP methods or injecting attacker-controlled headers.

Who is affected

Any project depending on the npm package axios within the affected version ranges is potentially impacted, though exposure to each individual issue depends on configuration and usage. CVE-2026-101901 and CVE-2026-101898 affect axios from 1.13.0 up to (but not including) 1.20.0. CVE-2026-101906 affects 1.15.0 up to 1.20.0. CVE-2026-101903 affects 1.16.1 up to 1.20.0. CVE-2026-101907 affects 1.17.0 up to 1.20.0. CVE-2026-101900 affects 1.12.0 up to 1.20.0. CVE-2026-101908 affects 1.7.0 up to 1.20.0. CVE-2026-101902 affects axios from 0.27.2 up to (but not including) 0.34.0, and separately from 1.0.0 up to (but not including) 1.20.0.

Affected and fixed versions

All eight issues are fixed in axios 1.20.0. For CVE-2026-101902, a fix is also available in the 0.x line at version 0.34.0 for applications still on that major version. Affected ranges by CVE: CVE-2026-101901 >= 1.13.0, < 1.20.0; CVE-2026-101906 >= 1.15.0, < 1.20.0; CVE-2026-101903 >= 1.16.1, < 1.20.0; CVE-2026-101907 >= 1.17.0, < 1.20.0; CVE-2026-101898 >= 1.13.0, < 1.20.0; CVE-2026-101902 >= 0.27.2, < 0.34.0 and >= 1.0.0, < 1.20.0; CVE-2026-101900 >= 1.12.0, < 1.20.0; CVE-2026-101908 >= 1.7.0, < 1.20.0.

Fixes and mitigation

The vendor has released axios 1.20.0, which resolves all eight vulnerabilities described above. Applications still on the 0.x release line should note that a fix for CVE-2026-101902 specifically is available in version 0.34.0. No additional workarounds are described in the available facts beyond upgrading.

Recommended action

Upgrade axios to version 1.20.0 as soon as practical. Projects that cannot yet move off the 0.x line and are specifically concerned about CVE-2026-101902 should upgrade to at least version 0.34.0, noting that the other seven issues are only resolved in 1.20.0. Because three of the issues are gadget vulnerabilities that depend on a separate prototype-pollution flaw elsewhere in the application, teams should also review their dependency tree for known prototype-pollution issues, independent of the axios upgrade. Review any code that relies on maxRedirects: 0, proxy configuration, or custom DNS lookup policies with the fetch or HTTP/2 adapters to confirm expected behavior after upgrading.

PatchBriefing score

5.8 / 10 · Medium

Official CVSS: 8.2

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Why this score

The highest-scored issues in this batch (CVE-2026-101901, CVE-2026-101906, CVE-2026-101903) carry a CVSS score of 8.2 and a PatchBriefing score of 5.8, reflecting network-exploitable denial-of-service conditions requiring no authentication or user interaction, in a very widely used package. The SSRF-related and redirect-bypass issues (CVE-2026-101898, CVE-2026-101907) score 7.0 CVSS / 5.2 PatchBriefing, reflecting high confidentiality/integrity impact on affected systems but a narrower precondition (specific proxy/DNS or maxRedirects configuration). The three prototype-pollution gadget issues (CVE-2026-101902, CVE-2026-101900, CVE-2026-101908) score 6.9 CVSS / 5.1 PatchBriefing; their real-world severity depends heavily on whether an application already has an independent prototype-pollution vulnerability, since axios does not introduce that primary flaw itself. None of the eight issues are flagged as known exploited or having public exploit code, and EPSS scores (where available) are low, in the 0.3–0.5 percentile range, indicating low observed exploitation likelihood at this time.

Affected versions

axios >= 1.13.0, < 1.20.0
vulnerable
≥ 1.20.0
patched
axios >= 1.15.0, < 1.20.0
vulnerable
≥ 1.20.0
patched
axios >= 1.16.1, < 1.20.0
vulnerable
≥ 1.20.0
patched
axios >= 1.17.0, < 1.20.0
vulnerable
≥ 1.20.0
patched
axios >= 1.13.0, < 1.20.0
vulnerable
≥ 1.20.0
patched
axios >= 1.0.0, < 1.20.0
vulnerable
≥ 0.34.0
patched
≥ 1.20.0
patched
axios >= 1.12.0, < 1.20.0
vulnerable
≥ 1.20.0
patched
axios >= 1.7.0, < 1.20.0
vulnerable
≥ 1.20.0
patched

Reported fixes

The vendor has released axios 1.20.0, which resolves all eight vulnerabilities described above. Applications still on the 0.x release line should note that a fix for CVE-2026-101902 specifically is available in version 0.34.0. No additional workarounds are described in the available facts beyond upgrading.

How this was built

16 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
  • GitHub Advisory Database database
  • NVD (NIST) database
  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
Axios 1.20.0 Fixes Eight Vulnerabilities: DoS, SSRF, and Prototype-Pollution Gadgets
1 article · 16 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email