HTTP Client Vulnerability in Axios Versions Affecting Node.js and Browser Applications
CVE-2026-101901

8.2HIGH

Key Information:

Vendor

AxiOS

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101901?

A vulnerability in Axios, a popular promise-based HTTP client for both browsers and Node.js, arises from insufficient error handling during the initialization or reuse of ClientHttp2Session. This issue affects Axios versions from 1.13.0 to 1.20.0. When utilizing HTTP/2, an unhandled error emitted during session management can circumvent standard Promise rejection processes. Consequently, this oversight may lead to unexpected terminations of the Node.js process, resulting in a denial of service. The vulnerability has been addressed in version 1.20.0.

Affected Version(s)

axios >= 1.13.0, < 1.20.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.