CVE-2026-101903
Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash characters on both sides of the media-type separator. An application passes an attacker-controlled malformed data URL containing many slash characters and no comma. the JavaScript regular-expression engine explores many separator placements before rejecting the URL. Synchronous excessive backtracking can block the Node.js event loop and cause denial of service. The affected identifiers are fromDataURI, DATA_URL_PATTERN, data:. This issue is fixed in version 1.20.0.
| CWE | CWE-1333 |
| Vendor | axios |
| Product | axios |
| Published | Sep 28, 2026 |
| Last Updated | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for axios axios
Be the first to know when new unknown vulnerabilities affecting axios axios are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
axios / axios
>= 1.16.1, < 1.20.0