Denial of Service Vulnerability in Axios HTTP Client
CVE-2026-101903
8.2HIGH
What is CVE-2026-101903?
A vulnerability in the Axios HTTP client allows for a denial of service due to excessive backtracking in the regular expression that validates data URLs. Specifically, versions 1.16.1 through 1.20.0 contain a flaw in the handling of malformed data URLs with excessive slash characters, which can lead the JavaScript engine to explore numerous separator placements before finally rejecting the input. This behavior can block the Node.js event loop, resulting in a denial of service when exploited by an attacker. The issue has been resolved in version 1.20.0.
Affected Version(s)
axios >= 1.16.1, < 1.20.0
