HTTP/2 Proxy Configuration Issue in Axios Client
CVE-2026-101898

7HIGH

Key Information:

Vendor

AxiOS

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101898?

The Axios HTTP client, which is widely used for making HTTP requests in both browser and Node.js environments, has a flaw that allows HTTP/2 requests to bypass designated proxy settings and caller-defined DNS lookup policies. This arises from improper configuration handling within versions 1.13.0 to 1.20.0, potentially leading to unintended connections that disregard user-defined proxy routes. The issue is rectified in version 1.20.0, ensuring compliance with configured proxy behaviors and DNS resolutions.

Affected Version(s)

axios >= 1.13.0, < 1.20.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.