Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Axios HTTP/2 Vulnerabilities Allow SSRF and DoS Attacks
October 1, 2026
Critical Node.js Vulnerability CVE-2024-27983 Allows Remote Code Execution
October 1, 2026
Critical Zimbra RCE Flaw CVE-2022-27925 Actively Exploited
October 1, 2026
Home/CyberSecurity News/Critical Axios HTTP/2 Vulnerabilities Allow SSRF and DoS Attacks
CyberSecurity News

Critical Axios HTTP/2 Vulnerabilities Allow SSRF and DoS Attacks

Key Takeaways Two critical vulnerabilities have been identified in Axios’s HTTP/2 implementation. These flaws enable Server-Side Request Forgery (SSRF) and Denial-of-Service (DoS) attacks....

Jennifer sherman
Jennifer sherman
October 1, 2026 3 Min Read
3 0

Key Takeaways

  • Two critical vulnerabilities have been identified in Axios’s HTTP/2 implementation.
  • These flaws enable Server-Side Request Forgery (SSRF) and Denial-of-Service (DoS) attacks.
  • Affected versions include Axios 1.13.0 through 1.19.x.
  • A patch is available in Axios version 1.20.0.

Axios, a widely used HTTP client, has disclosed two high-severity vulnerabilities within its HTTP/2 implementation. These security flaws could allow malicious actors to bypass crucial outbound network controls or trigger crashes in vulnerable Node.js applications. The issues impact Axios versions ranging from 1.13.0 to 1.19.x; developers are urged to upgrade to version 1.20.0, which includes the necessary fixes.

Table Of Content

  • Key Takeaways
  • SSRF Vulnerability: Bypassing Network Controls
  • Denial-of-Service Vulnerability: Uncaught Exceptions
  • What You Should Do

SSRF Vulnerability: Bypassing Network Controls

The first vulnerability, identified as GHSA-3pq3-5fj3-cg6v and CVE-2026-101898, specifically targets Axios applications that utilize HTTP/2 requests in conjunction with custom DNS lookup functions or explicit proxy configurations. Under certain conditions, Axios may fail to properly apply caller-supplied settings for DNS lookup policies, explicit proxy settings, or proxy configurations inherited from environment variables before establishing an HTTP/2 connection.

This oversight creates a significant Server-Side Request Forgery (SSRF) risk, particularly in applications that process user-controlled URLs. It undermines common security measures where organizations employ custom DNS resolvers to block access to internal IP addresses, cloud metadata services, localhost targets, or private network ranges. Furthermore, deployments that route all outbound traffic through an inspection proxy are also at risk. The flawed HTTP/2 code path could allow Axios to establish a direct connection to a destination, effectively circumventing these established protections.

An attacker could exploit this vulnerability by manipulating an application that passes a user-influenced destination into Axios with the httpVersion: 2 setting. For instance, a web service designed to retrieve external URLs might implement a DNS allowlist to prevent requests to sensitive targets like 127.0.0.1, RFC1918 networks, or cloud metadata endpoints. If this service switches to the affected HTTP/2 adapter, Axios could bypass the custom lookup or proxy route, sending a direct request to a restricted internal resource.

Denial-of-Service Vulnerability: Uncaught Exceptions

The second vulnerability, tracked as GHSA-542g-h47m-68v8 and CVE-2026-101901, poses a denial-of-service threat to Node.js applications. This flaw stems from inadequate error handling within Axios for a ClientHttp2Session during HTTP/2 session initialization or reuse. When such a session emits an error event, the event may escape Axios’s standard Promise rejection handling mechanisms, resulting in an uncaught exception.

In the Node.js environment, an unhandled error event can lead to the termination of the running process. Consequently, an attacker capable of influencing a request flow that initiates or reuses an Axios HTTP/2 session could potentially force an affected service offline. The practical risk of this vulnerability is highest for applications that use Axios to fetch attacker-controlled URLs, interact with external integrations, process webhooks, or proxy requests to user-specified hosts.

The Axios advisory covers two high-severity flaws that emerged following the integration of HTTP/2 support into its Node.js HTTP adapter in version 1.13.0.

What You Should Do

  • Organizations should immediately upgrade Axios to version 1.20.0 or a later release to implement the official fix.
  • As a temporary mitigation measure until patching is complete, teams should disable HTTP/2 requests by removing the httpVersion: 2 setting or explicitly configuring HTTP/1.1.
  • Defenders must thoroughly review applications that fetch user-supplied URLs to ensure robust validation of destination hosts before initiating any requests.
  • Maintain robust egress filtering at the network layer, independent of application-level controls, to prevent unauthorized outbound connections.
  • Continuously monitor outbound network connections for any unexpected access attempts to internal resources or cloud metadata services.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEPatchSecurity

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical Node.js Vulnerability CVE-2024-27983 Allows Remote Code Execution

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical PS5 Kernel Exploit Affects All Firmware Versions
October 1, 2026
New CPU Attack Steals Linux Root Password Hashes from Memory
October 1, 2026
Critical MikroTik RouterOS Flaw (CVE-2023-30799) Allows Code Execution
October 1, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us