CVE-2026-101898
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup does not consistently apply proxy settings and caller-supplied DNS lookup policy. An HTTPS request uses httpVersion: 2 with explicit config.proxy or environment-derived proxy settings, or relies on caller-supplied config.lookup DNS policy. The HTTP/2 path can connect without the configured proxy behavior or without applying the caller-supplied config.lookup policy before http2.connect(). Requests can bypass the intended proxy route or the caller-supplied DNS resolution policy. This issue is fixed in version 1.20.0.
| CWE | CWE-918 |
| Vendor | axios |
| Product | axios |
| Published | Sep 28, 2026 |
| Last Updated | Sep 28, 2026 |
Get instant alerts for axios axios
Be the first to know when new unknown vulnerabilities affecting axios axios are published โ delivered to Slack, Telegram or Discord.