CVE-2026-101901
Received Received - Intake

HTTP/2 Session Error Handling Flaw in Axios

Vulnerability report for CVE-2026-101901, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse. A request uses httpVersion: 2 and the ClientHttp2Session emits an error during session initialization or reuse. The unhandled session error escapes normal Promise rejection handling. The uncaught error can terminate the Node.js process and cause denial of service. This issue is fixed in version 1.20.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
axios axios to 1.20.0 (inc)
axios axios From 1.13.0 (inc) to 1.20.0 (inc)
axios axios 1.20.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Denial of Service (DoS) vulnerability in the Axios library affecting versions 1.13.0 to 1.20.0 when using Node.js HTTP/2 support. Axios fails to handle 'error' events from ClientHttp2Session objects during HTTP/2 client initialization. Unhandled errors bypass Promise rejection and terminate the Node.js process.

Detection Guidance

To detect this vulnerability, check if your Axios version is between 1.13.0 and 1.20.0 and if your application uses Node.js HTTP/2 support with httpVersion set to 2. Run 'npm list axios' to verify the installed version. Inspect application logs for Node.js process crashes during HTTP/2 requests.

Impact Analysis

Attackers can crash your Node.js process by exploiting this vulnerability, leading to service disruption. This happens if your application uses HTTP/2 with httpVersion set to 2 and the ClientHttp2Session emits an error during initialization or reuse.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by causing service disruptions due to Node.js process termination. GDPR requires maintaining service availability, and HIPAA mandates continuous access to protected health information systems. Unplanned outages from DoS conditions may violate these requirements.

Mitigation Strategies

Upgrade Axios to version 1.20.0 or later immediately. If upgrading is not possible, disable HTTP/2 support for untrusted destinations or avoid using attacker-controlled values in http2Options configuration. Review and update request configurations to ensure proper error handling.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101901. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart