{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aaxiosaxiosnode.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"id":"CVE-2026-101901"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["axios (\u003e= 1.13.0, \u003c 1.20.0)"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","nodejs","software-vulnerability"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAxios versions 1.13.0 through 1.19.x contain a vulnerability in the handling of Node.js HTTP/2 sessions. When using the HTTP/2 adapter, Axios establishes connections using the Node.js 'http2' module. The internal session management logic fails to attach an 'error' event listener to the initialized 'ClientHttp2Session' objects. If a network error, connection failure, or server-side rejection occurs during session initialization, the Node.js runtime treats the resulting error as an unhandled EventEmitter exception. This behavior bypasses standard Axios Promise rejection patterns, leading to an immediate termination of the application process.\u003c/p\u003e\n\u003cp\u003eThis issue is specific to configurations where 'httpVersion' is set to 2. Applications using default HTTP/1.1 settings or those utilizing browser-based XHR/fetch adapters are not affected. Defenders should prioritize auditing applications that interface with user-supplied or untrusted URLs via HTTP/2, as these provide the most direct vector for triggering the unhandled exception and achieving a denial-of-service state.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe application initializes an Axios instance with \u003ccode\u003ehttpVersion: 2\u003c/code\u003e configured.\u003c/li\u003e\n\u003cli\u003eThe application triggers an outgoing HTTP request to a destination controlled or influenced by an attacker.\u003c/li\u003e\n\u003cli\u003eAxios calls \u003ccode\u003ehttp2.connect()\u003c/code\u003e to initialize a new session with the target authority.\u003c/li\u003e\n\u003cli\u003eThe remote target (or network intermediary) forces a connection error (e.g., reset, connection refused, or TLS failure).\u003c/li\u003e\n\u003cli\u003eThe underlying \u003ccode\u003eClientHttp2Session\u003c/code\u003e object emits an 'error' event to the process.\u003c/li\u003e\n\u003cli\u003eBecause no error listener is attached within the Axios session manager, the Node.js process treats the error as an uncaught exception.\u003c/li\u003e\n\u003cli\u003eThe application process exits abruptly, resulting in a denial-of-service for all concurrent users.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in an immediate denial-of-service for the vulnerable Node.js process. This can impact service availability for any users of the application. The vulnerability is highly disruptive in high-traffic microservices or web applications that rely on Axios for backend-to-backend communication, as a single malicious or malformed request can crash the entire service instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade to Axios version 1.20.0 or later immediately to incorporate the necessary 'error' event handling logic.\u003c/li\u003e\n\u003cli\u003eFor environments where immediate patching is not feasible, disable the use of the HTTP/2 adapter in Axios for any request destinations that involve user input or untrusted origins.\u003c/li\u003e\n\u003cli\u003eReview application configurations to ensure 'http2Options' are not derived from raw, unvalidated user-controlled input, as this increases the likelihood of triggering edge-case connection failures.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-30T16:28:16Z","date_published":"2026-09-30T16:28:16Z","id":"https://feed.craftedsignal.io/briefs/2026-09-axios-dos/","summary":"Axios versions prior to 1.20.0 are vulnerable to a denial-of-service condition where unhandled 'error' events on ClientHttp2Session objects cause the parent Node.js process to terminate.","title":"Denial of Service in Axios via Unhandled HTTP/2 Session Errors","url":"https://feed.craftedsignal.io/briefs/2026-09-axios-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}