๐Ÿ” CVE Alert

CVE-2026-101901

UNKNOWN 0.0

Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse. A request uses httpVersion: 2 and the ClientHttp2Session emits an error during session initialization or reuse. The unhandled session error escapes normal Promise rejection handling. The uncaught error can terminate the Node.js process and cause denial of service. This issue is fixed in version 1.20.0.

CWE CWE-400
Vendor axios
Product axios
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for axios axios

Be the first to know when new unknown vulnerabilities affecting axios axios are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

axios / axios
>= 1.13.0, < 1.20.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/axios/axios/security/advisories/GHSA-542g-h47m-68v8 github.com: https://github.com/axios/axios/pull/11141 github.com: https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a github.com: https://github.com/axios/axios/releases/tag/v1.20.0