<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Axios (&gt;= 1.13.0, &lt; 1.20.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/axios--1.13.0--1.20.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 16:28:16 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/axios--1.13.0--1.20.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service in Axios via Unhandled HTTP/2 Session Errors</title><link>https://feed.craftedsignal.io/briefs/2026-09-axios-dos/</link><pubDate>Wed, 30 Sep 2026 16:28:16 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-axios-dos/</guid><description>Axios versions prior to 1.20.0 are vulnerable to a denial-of-service condition where unhandled 'error' events on ClientHttp2Session objects cause the parent Node.js process to terminate.</description><content:encoded><![CDATA[<p>Axios versions 1.13.0 through 1.19.x contain a vulnerability in the handling of Node.js HTTP/2 sessions. When using the HTTP/2 adapter, Axios establishes connections using the Node.js 'http2' module. The internal session management logic fails to attach an 'error' event listener to the initialized 'ClientHttp2Session' objects. If a network error, connection failure, or server-side rejection occurs during session initialization, the Node.js runtime treats the resulting error as an unhandled EventEmitter exception. This behavior bypasses standard Axios Promise rejection patterns, leading to an immediate termination of the application process.</p>
<p>This issue is specific to configurations where 'httpVersion' is set to 2. Applications using default HTTP/1.1 settings or those utilizing browser-based XHR/fetch adapters are not affected. Defenders should prioritize auditing applications that interface with user-supplied or untrusted URLs via HTTP/2, as these provide the most direct vector for triggering the unhandled exception and achieving a denial-of-service state.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The application initializes an Axios instance with <code>httpVersion: 2</code> configured.</li>
<li>The application triggers an outgoing HTTP request to a destination controlled or influenced by an attacker.</li>
<li>Axios calls <code>http2.connect()</code> to initialize a new session with the target authority.</li>
<li>The remote target (or network intermediary) forces a connection error (e.g., reset, connection refused, or TLS failure).</li>
<li>The underlying <code>ClientHttp2Session</code> object emits an 'error' event to the process.</li>
<li>Because no error listener is attached within the Axios session manager, the Node.js process treats the error as an uncaught exception.</li>
<li>The application process exits abruptly, resulting in a denial-of-service for all concurrent users.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in an immediate denial-of-service for the vulnerable Node.js process. This can impact service availability for any users of the application. The vulnerability is highly disruptive in high-traffic microservices or web applications that rely on Axios for backend-to-backend communication, as a single malicious or malformed request can crash the entire service instance.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade to Axios version 1.20.0 or later immediately to incorporate the necessary 'error' event handling logic.</li>
<li>For environments where immediate patching is not feasible, disable the use of the HTTP/2 adapter in Axios for any request destinations that involve user input or untrusted origins.</li>
<li>Review application configurations to ensure 'http2Options' are not derived from raw, unvalidated user-controlled input, as this increases the likelihood of triggering edge-case connection failures.</li>
</ol>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>denial-of-service</category><category>nodejs</category><category>software-vulnerability</category></item><item><title>Axios Fetch Adapter Fails to Enforce Redirect Limits</title><link>https://feed.craftedsignal.io/briefs/2026-09-axios-ssrf-bypass/</link><pubDate>Wed, 30 Sep 2026 16:27:51 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-axios-ssrf-bypass/</guid><description>The Axios fetch adapter fails to enforce the maxRedirects: 0 configuration, enabling redirect-based SSRF by allowing requests to follow unexpected internal redirects.</description><content:encoded><![CDATA[<p>The Axios library provides a <code>maxRedirects</code> configuration option, frequently used by developers to mitigate redirect-based Server-Side Request Forgery (SSRF) by setting the limit to <code>0</code>. While the standard Node.js HTTP adapter correctly respects this constraint, the <code>fetch</code> adapter implemented in <code>lib/adapters/fetch.js</code> ignores this setting.</p>
<p>When applications rely on the <code>fetch</code> adapter, either through explicit configuration, environment-specific resolution (such as in Deno, Bun, or Cloudflare Workers), or automatic adapter selection, the library fails to pass a restrictive <code>redirect</code> mode to the underlying <code>fetch()</code> API. Consequently, the default runtime behavior of <code>redirect: 'follow'</code> takes precedence. This discrepancy allows attackers who can influence the initial request URL or provide a malicious redirecting server to bypass intended SSRF protections, leading to potential unauthorized access to internal resources or state-changing operations on internal endpoints reachable from the application environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for redirect-based SSRF, which may lead to the exposure of sensitive internal data or unauthorized modification of internal system states. The impact is significant for applications operating in cloud or serverless environments where network perimeter defenses are often bypassed by internal requests. If an internal service processes state-changing requests without additional authentication, an attacker can trigger unauthorized mutations by providing an open redirect or a malicious redirection chain that directs the application to the internal target.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Detection and remediation should focus on identifying applications using the fetch adapter in security-sensitive contexts.</p>
<ul>
<li>Audit application code for usages of <code>axios.get()</code> or <code>axios.request()</code> that specify <code>maxRedirects: 0</code> without explicit <code>fetchOptions</code> to define redirect behavior.</li>
<li>Where the fetch adapter is required, enforce manual redirect handling by setting <code>fetchOptions: { redirect: 'manual' }</code> in the axios configuration.</li>
<li>If the application environment supports it, prefer the Node.js HTTP adapter for requests requiring strict adherence to redirect limits.</li>
<li>Implement network-level egress filtering to prevent the application server from initiating connections to sensitive internal service segments (127.0.0.1, 169.254.169.254, or private RFC1918 ranges) unless explicitly required.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>prototype-pollution</category><category>javascript</category><category>nodejs</category><category>supply-chain</category><category>ssrf</category><category>library-vulnerability</category></item></channel></rss>