Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101898— Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls

Quick assessment

Affected
axios axios
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Axios 是一个面向浏览器和 Node.js 的基于 Promise 的 HTTP 客户端。在版本 1.13.0 至 1.20.0 之间,Axios 的 HTTP/2 请求设置未能一致地应用代理配置以及调用方提供的 DNS 查找策略。当发起 HTTPS 请求并使用 时,若显式配置了代理( )或通过环境变量派生出代理设置,或者依赖于调用方提供的 DNS 策略,则问题尤为突出。在调用 之前,HTTP/2 路径可能未按配置的代理行为正确连接,或未应用调用方指定的 DNS 解析策略。这导致请求可能绕过预期的代理路由或调用

CVSS 7.0 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
axios axios >= 1.13.0, < 1.20.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101898

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
Source: CVE Program / CVE List V5
Vulnerability Description
Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup does not consistently apply proxy settings and caller-supplied DNS lookup policy. An HTTPS request uses httpVersion: 2 with explicit config.proxy or environment-derived proxy settings, or relies on caller-supplied config.lookup DNS policy. The HTTP/2 path can connect without the configured proxy behavior or without applying the caller-supplied config.lookup policy before http2.connect(). Requests can bypass the intended proxy route or the caller-supplied DNS resolution policy. This issue is fixed in version 1.20.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
axios axios >= 1.13.0, < 1.20.0 -

II. Public POCs for CVE-2026-101898

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101898

请登录查看更多情报信息。

Other References for CVE-2026-101898 (4)

Same Patch Batch · axios · 2026-09-28 · 11 CVEs total

CVE-2026-101909 8.3 HIGH Axios: Prototype Pollution Gadget in axios toFormData Options
CVE-2026-101901 8.2 HIGH Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initial
CVE-2026-101906 8.2 HIGH Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redi
CVE-2026-101903 8.2 HIGH Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)
CVE-2026-101905 7.6 HIGH Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inher
CVE-2026-101907 7.0 HIGH Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF
CVE-2026-101900 6.9 MEDIUM Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders
CVE-2026-101902 6.9 MEDIUM Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototyp
CVE-2026-101904 6.9 MEDIUM Axios: Header Injection via Inherited headers After Minimal Interceptor
CVE-2026-101908 6.9 MEDIUM Axios: Prototype pollution gadget in fetch adapter can alter outbound requests

IV. Related Vulnerabilities

V. Comments for CVE-2026-101898

No comments yet


Leave a comment