Product
medium
advisory
Denial of Service in Axios via Unhandled HTTP/2 Session Errors
1 CVEAxios versions prior to 1.20.0 are vulnerable to a denial-of-service condition where unhandled 'error' events on ClientHttp2Session objects cause the parent Node.js process to terminate.
axios
denial-of-service
nodejs
software-vulnerability
1c
high
advisory
Axios Fetch Adapter Fails to Enforce Redirect Limits
2 TTPsThe Axios fetch adapter fails to enforce the maxRedirects: 0 configuration, enabling redirect-based SSRF by allowing requests to follow unexpected internal redirects.
axios +3
prototype-pollution
javascript
nodejs
supply-chain
ssrf
library-vulnerability
2t