Critical Axios HTTP/2 Vulnerabilities Allow SSRF and DoS Attacks
Key Takeaways Two critical vulnerabilities have been identified in Axios’s HTTP/2 implementation. These flaws enable Server-Side Request Forgery (SSRF) and Denial-of-Service (DoS) attacks....
Key Takeaways
- Two critical vulnerabilities have been identified in Axios’s HTTP/2 implementation.
- These flaws enable Server-Side Request Forgery (SSRF) and Denial-of-Service (DoS) attacks.
- Affected versions include Axios 1.13.0 through 1.19.x.
- A patch is available in Axios version 1.20.0.
Axios, a widely used HTTP client, has disclosed two high-severity vulnerabilities within its HTTP/2 implementation. These security flaws could allow malicious actors to bypass crucial outbound network controls or trigger crashes in vulnerable Node.js applications. The issues impact Axios versions ranging from 1.13.0 to 1.19.x; developers are urged to upgrade to version 1.20.0, which includes the necessary fixes.
Table Of Content
SSRF Vulnerability: Bypassing Network Controls
The first vulnerability, identified as GHSA-3pq3-5fj3-cg6v and CVE-2026-101898, specifically targets Axios applications that utilize HTTP/2 requests in conjunction with custom DNS lookup functions or explicit proxy configurations. Under certain conditions, Axios may fail to properly apply caller-supplied settings for DNS lookup policies, explicit proxy settings, or proxy configurations inherited from environment variables before establishing an HTTP/2 connection.
This oversight creates a significant Server-Side Request Forgery (SSRF) risk, particularly in applications that process user-controlled URLs. It undermines common security measures where organizations employ custom DNS resolvers to block access to internal IP addresses, cloud metadata services, localhost targets, or private network ranges. Furthermore, deployments that route all outbound traffic through an inspection proxy are also at risk. The flawed HTTP/2 code path could allow Axios to establish a direct connection to a destination, effectively circumventing these established protections.
An attacker could exploit this vulnerability by manipulating an application that passes a user-influenced destination into Axios with the httpVersion: 2 setting. For instance, a web service designed to retrieve external URLs might implement a DNS allowlist to prevent requests to sensitive targets like 127.0.0.1, RFC1918 networks, or cloud metadata endpoints. If this service switches to the affected HTTP/2 adapter, Axios could bypass the custom lookup or proxy route, sending a direct request to a restricted internal resource.
Denial-of-Service Vulnerability: Uncaught Exceptions
The second vulnerability, tracked as GHSA-542g-h47m-68v8 and CVE-2026-101901, poses a denial-of-service threat to Node.js applications. This flaw stems from inadequate error handling within Axios for a ClientHttp2Session during HTTP/2 session initialization or reuse. When such a session emits an error event, the event may escape Axios’s standard Promise rejection handling mechanisms, resulting in an uncaught exception.
In the Node.js environment, an unhandled error event can lead to the termination of the running process. Consequently, an attacker capable of influencing a request flow that initiates or reuses an Axios HTTP/2 session could potentially force an affected service offline. The practical risk of this vulnerability is highest for applications that use Axios to fetch attacker-controlled URLs, interact with external integrations, process webhooks, or proxy requests to user-specified hosts.
The Axios advisory covers two high-severity flaws that emerged following the integration of HTTP/2 support into its Node.js HTTP adapter in version 1.13.0.
What You Should Do
- Organizations should immediately upgrade Axios to version 1.20.0 or a later release to implement the official fix.
- As a temporary mitigation measure until patching is complete, teams should disable HTTP/2 requests by removing the
httpVersion: 2setting or explicitly configuring HTTP/1.1. - Defenders must thoroughly review applications that fetch user-supplied URLs to ensure robust validation of destination hosts before initiating any requests.
- Maintain robust egress filtering at the network layer, independent of application-level controls, to prevent unauthorized outbound connections.
- Continuously monitor outbound network connections for any unexpected access attempts to internal resources or cloud metadata services.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.