Two serious security flaws in Axios have been revealed, impacting versions 1.13.0 through 1.19.x. These vulnerabilities concern Axios’s support for HTTP/2 in Node.js and open doors for attackers to bypass network security controls or bring apps down via denial of service. A fixed release (version 1.20.0) has been issued.
How the Vulnerabilities Work
The first issue, tracked as GHSA-3pq3-5fj3-cg6v (CVE-2026-101898), arises when Axios uses HTTP/2 together with user-provided DNS lookup routines or proxy settings. In these cases, Axios may ignore configurations meant to restrict outgoing connections. That means custom DNS resolvers, proxy setups, or environment-based proxy configurations might not be applied before HTTP/2 connections are initiated.
The bypass allows attackers—particularly in applications that allow user-input URLs—to reach restricted targets like localhost, private network IPs, or cloud metadata endpoints, despite protections in place. Overlooked DNS checks or allowlists become ineffective under the vulnerable HTTP/2 path.
Denial of Service via Unhandled HTTP/2 Session Errors
The second flaw, GHSA-542g-h47m-68v8 (CVE-2026-101901), stems from inadequate handling of error events in HTTP/2 sessions. When a ClientHttp2Session throws an error—either during setup or reuse—Axios may not catch it. The result: an uncaught exception that can crash the entire Node.js application.
This becomes especially dangerous in services that fetch URLs from users, act as proxies to external systems, process webhooks, or make outbound HTTP requests generally. An attacker influencing one such endpoint could effectively shut down a service.
Who’s At Risk & How to Mitigate
Applications using Axios 1.13.0–1.19.x and relying on HTTP/2 are vulnerable. Any system that:
- fetches user-supplied URLs,
- uses custom DNS resolution or proxy enforcement,
- processes external integrations or proxies to user-controlled hosts,
- handles webhooks or makes arbitrary outbound requests
…is exposed to SSRF bypass or remote denial of service.
The recommended fix is to upgrade Axios to version 1.20.0 or newer. Until then, developers should disable HTTP/2 by removing or avoiding the option `httpVersion: 2` so that requests fall back to HTTP/1.1. Additionally, perform destination hostname validation before making requests, enforce egress controls outside the app logic (firewalls, network layer), and monitor outgoing traffic for signs of internal or metadata service access.
This issue emerged after HTTP/2 support was introduced in Axios’s Node.js HTTP adapter in version 1.13.0.
Why This Matters:Axios is one of the most widely used HTTP clients in JavaScript/Node.js. These vulnerabilities expose a blind spot where built-in safeguards like DNS allowlists or proxy restrictions are silently bypassed under HTTP/2. Attackers who have a vector to supply URLs can exploit this to access sensitive internal systems or destabilize services. Teams using Axios for external integrations, API gateways, webhooks, or proxying must act quickly.