Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101906— Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location

Quick assessment

Affected
axios axios
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Axios 是一个基于 Promise 的 HTTP 客户端,适用于浏览器和 Node.js 环境。从版本 1.15.0 到 1.20.0,Axios 中的 函数在处理重定向主机名时,使用了二次回溯(quadratic)特性的结尾点号正则表达式。当系统中配置了 或 环境变量,且 或 不为空时,若启用了重定向跟随,且经过精心构造的重定向响应头 中包含大量连续的点号后跟一个非点号字符,则会在处理该恶意主机名时引发正则表达式在 操作中产生二次回溯,从而导致严重性能问题。这种同步的正则表达式处理会阻塞 Node.js 的事

CVSS 8.2 · High

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 1

VendorProduct Version RangeStatus
axios axios >= 1.15.0, < 1.20.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101906

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location
Source: CVE Program / CVE List V5
Vulnerability Description
Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.0 until 1.20.0, Axios shouldBypassProxy applies a quadratic trailing-dot regular expression to redirect hostnames. HTTP_PROXY or HTTPS_PROXY is configured, NO_PROXY or no_proxy is non-empty, redirects are followed, and a crafted redirect Location contains many dots followed by a non-dot character. Hostname.replace(/.+$/, '') backtracks quadratically while processing the crafted redirect hostname. Synchronous regular-expression processing can block the Node.js event loop and cause denial of service. This issue is fixed in version 1.20.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
axios axios >= 1.15.0, < 1.20.0 -

II. Public POCs for CVE-2026-101906

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101906

请登录查看更多情报信息。

Other References for CVE-2026-101906 (4)

Same Patch Batch · axios · 2026-09-28 · 11 CVEs total

CVE-2026-101909 8.3 HIGH Axios: Prototype Pollution Gadget in axios toFormData Options
CVE-2026-101901 8.2 HIGH Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initial
CVE-2026-101903 8.2 HIGH Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)
CVE-2026-101905 7.6 HIGH Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inher
CVE-2026-101898 7.0 HIGH Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
CVE-2026-101907 7.0 HIGH Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF
CVE-2026-101900 6.9 MEDIUM Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders
CVE-2026-101902 6.9 MEDIUM Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototyp
CVE-2026-101904 6.9 MEDIUM Axios: Header Injection via Inherited headers After Minimal Interceptor
CVE-2026-101908 6.9 MEDIUM Axios: Prototype pollution gadget in fetch adapter can alter outbound requests

IV. Related Vulnerabilities

V. Comments for CVE-2026-101906

No comments yet


Leave a comment