Axios 是一个面向浏览器和 Node.js 的基于 Promise 的 HTTP 客户端。在版本 1.13.0 至 1.20.0 之间,Axios 在 HTTP/2 会话初始化或复用过程中,未能为 提供充分的错误处理机制。当请求使用 且 在会话初始化或复用期间触发错误时,该未处理的会话错误会绕过正常的 Promise 拒绝处理流程。由此引发的未捕获错误可能导致 Node.js 进程终止,从而造成拒绝服务(DoS)。该问题已在版本 1.20.0 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101909 | 8.3 HIGH | Axios: Prototype Pollution Gadget in axios toFormData Options |
| CVE-2026-101906 | 8.2 HIGH | Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redi |
| CVE-2026-101903 | 8.2 HIGH | Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) |
| CVE-2026-101905 | 7.6 HIGH | Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inher |
| CVE-2026-101898 | 7.0 HIGH | Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls |
| CVE-2026-101907 | 7.0 HIGH | Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF |
| CVE-2026-101900 | 6.9 MEDIUM | Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders |
| CVE-2026-101902 | 6.9 MEDIUM | Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototyp |
| CVE-2026-101904 | 6.9 MEDIUM | Axios: Header Injection via Inherited headers After Minimal Interceptor |
| CVE-2026-101908 | 6.9 MEDIUM | Axios: Prototype pollution gadget in fetch adapter can alter outbound requests |
No comments yet