CVE-2026-101901: Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization
Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse. A request uses httpVersion: 2 and the ClientHttp2Session emits an error during session initialization or reuse. The unhandled session error escapes normal Promise rejection handling. The uncaught error can terminate the Node.js process and cause denial of service. This issue is fixed in version 1.20.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
axiosto a version that resolves this vulnerability.Fixed in 1.20.0
Event History
Frequently Asked Questions
Which deployments are exposed to this denial-of-service condition?
Node.js applications using Axios versions from 1.13.0 up to, but not including, 1.20.0 are exposed when they make requests with httpVersion set to 2. Browser-only Axios use is not identified as affected by the provided information.
What must occur for an attacker to trigger the process crash?
An Axios request must use HTTP/2, and the associated ClientHttp2Session must emit an error while the session is being initialized or reused. The unhandled error can escape Promise rejection handling and terminate the Node.js process.
What is the remediation?
Upgrade Axios to version 1.20.0, which fixes the inadequate ClientHttp2Session error handling. If an immediate upgrade is not possible, avoid making Axios requests with httpVersion: 2.
How can I determine whether my application is at risk?
Check whether the application uses npm/axios in a version from 1.13.0 through 1.19.x and whether any Axios request configuration sets httpVersion to 2. Review process-terminating uncaught errors associated with ClientHttp2Session initialization or reuse.