Denial of Service in Axios via Unhandled HTTP/2 Session Errors
Axios versions prior to 1.20.0 are vulnerable to a denial-of-service condition where unhandled 'error' events on ClientHttp2Session objects cause the parent Node.js process to terminate.
CVE search metadata
CVE search record: CVE-2026-101901. EPSS: 0.38%. KEV: no. Product: axios (>= 1.13.0, < 1.20.0). Brief: Denial of Service in Axios via Unhandled HTTP/2 Session Errors. Brief link: https://feed.craftedsignal.io/briefs/2026-09-axios-dos/
Axios versions 1.13.0 through 1.19.x contain a vulnerability in the handling of Node.js HTTP/2 sessions. When using the HTTP/2 adapter, Axios establishes connections using the Node.js 'http2' module. The internal session management logic fails to attach an 'error' event listener to the initialized 'ClientHttp2Session' objects. If a network error, connection failure, or server-side rejection occurs during session initialization, the Node.js runtime treats the resulting error as an unhandled EventEmitter exception. This behavior bypasses standard Axios Promise rejection patterns, leading to an immediate termination of the application process.
This issue is specific to configurations where 'httpVersion' is set to 2. Applications using default HTTP/1.1 settings or those utilizing browser-based XHR/fetch adapters are not affected. Defenders should prioritize auditing applications that interface with user-supplied or untrusted URLs via HTTP/2, as these provide the most direct vector for triggering the unhandled exception and achieving a denial-of-service state.
Attack Chain
- The application initializes an Axios instance with
httpVersion: 2configured. - The application triggers an outgoing HTTP request to a destination controlled or influenced by an attacker.
- Axios calls
http2.connect()to initialize a new session with the target authority. - The remote target (or network intermediary) forces a connection error (e.g., reset, connection refused, or TLS failure).
- The underlying
ClientHttp2Sessionobject emits an 'error' event to the process. - Because no error listener is attached within the Axios session manager, the Node.js process treats the error as an uncaught exception.
- The application process exits abruptly, resulting in a denial-of-service for all concurrent users.
Impact
Successful exploitation results in an immediate denial-of-service for the vulnerable Node.js process. This can impact service availability for any users of the application. The vulnerability is highly disruptive in high-traffic microservices or web applications that rely on Axios for backend-to-backend communication, as a single malicious or malformed request can crash the entire service instance.
Recommendation
- Upgrade to Axios version 1.20.0 or later immediately to incorporate the necessary 'error' event handling logic.
- For environments where immediate patching is not feasible, disable the use of the HTTP/2 adapter in Axios for any request destinations that involve user input or untrusted origins.
- Review application configurations to ensure 'http2Options' are not derived from raw, unvalidated user-controlled input, as this increases the likelihood of triggering edge-case connection failures.
Immediate actions
Upgrade Axios to version 1.20.0 or later
Mitigations
Disable HTTP/2 support in Axios configurations for untrusted destinations
CVE-2026-101901