HTTP Client Vulnerability in Axios Versions Affecting Node.js and Browser Applications
CVE-2026-101901
8.2HIGH
What is CVE-2026-101901?
A vulnerability in Axios, a popular promise-based HTTP client for both browsers and Node.js, arises from insufficient error handling during the initialization or reuse of ClientHttp2Session. This issue affects Axios versions from 1.13.0 to 1.20.0. When utilizing HTTP/2, an unhandled error emitted during session management can circumvent standard Promise rejection processes. Consequently, this oversight may lead to unexpected terminations of the Node.js process, resulting in a denial of service. The vulnerability has been addressed in version 1.20.0.
Affected Version(s)
axios >= 1.13.0, < 1.20.0
