HTTP/2 Proxy Configuration Issue in Axios Client
CVE-2026-101898
7HIGH
What is CVE-2026-101898?
The Axios HTTP client, which is widely used for making HTTP requests in both browser and Node.js environments, has a flaw that allows HTTP/2 requests to bypass designated proxy settings and caller-defined DNS lookup policies. This arises from improper configuration handling within versions 1.13.0 to 1.20.0, potentially leading to unintended connections that disregard user-defined proxy routes. The issue is rectified in version 1.20.0, ensuring compliance with configured proxy behaviors and DNS resolutions.
Affected Version(s)
axios >= 1.13.0, < 1.20.0
