Denial of Service Vulnerability in Axios HTTP Client
CVE-2026-101903

8.2HIGH

Key Information:

Vendor

AxiOS

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101903?

A vulnerability in the Axios HTTP client allows for a denial of service due to excessive backtracking in the regular expression that validates data URLs. Specifically, versions 1.16.1 through 1.20.0 contain a flaw in the handling of malformed data URLs with excessive slash characters, which can lead the JavaScript engine to explore numerous separator placements before finally rejecting the input. This behavior can block the Node.js event loop, resulting in a denial of service when exploited by an attacker. The issue has been resolved in version 1.20.0.

Affected Version(s)

axios >= 1.16.1, < 1.20.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.