CVE-2026-101903: Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)
Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash characters on both sides of the media-type separator. An application passes an attacker-controlled malformed data URL containing many slash characters and no comma. the JavaScript regular-expression engine explores many separator placements before rejecting the URL. Synchronous excessive backtracking can block the Node.js event loop and cause denial of service. The affected identifiers are fromDataURI, DATAURLPATTERN, data:. This issue is fixed in version 1.20.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Axiosto a version that resolves this vulnerability.Fixed in 1.20.0
Event History
Frequently Asked Questions
Which Axios versions require remediation?
Axios versions 1.16.1 through versions before 1.20.0 are affected. Upgrade to 1.20.0, which contains the fix.
Which applications are realistically exposed to denial of service?
The documented impact applies to Node.js applications that pass attacker-controlled data: URLs to Axios's fromDataURI parsing path. The excessive regular-expression backtracking can synchronously block the Node.js event loop.
What input is needed to trigger the issue?
An attacker needs to supply a malformed data URL with many slash characters and no comma. This causes the parser's regular expression to try many possible media-type separator placements before rejecting the value.