šŸ” CVE Alert

CVE-2026-101906

UNKNOWN 0.0

Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.0 until 1.20.0, Axios shouldBypassProxy applies a quadratic trailing-dot regular expression to redirect hostnames. HTTP_PROXY or HTTPS_PROXY is configured, NO_PROXY or no_proxy is non-empty, redirects are followed, and a crafted redirect Location contains many dots followed by a non-dot character. Hostname.replace(/.+$/, '') backtracks quadratically while processing the crafted redirect hostname. Synchronous regular-expression processing can block the Node.js event loop and cause denial of service. This issue is fixed in version 1.20.0.

CWE CWE-400 CWE-1333
Vendor axios
Product axios
Published Sep 28, 2026
Last Updated Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for axios axios

Be the first to know when new unknown vulnerabilities affecting axios axios are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free Ā· No credit card Ā· 60 sec setup

Affected Versions

axios / axios
>= 1.15.0, < 1.20.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/axios/axios/security/advisories/GHSA-mghh-pgcx-3jjj github.com: https://github.com/axios/axios/pull/11141 github.com: https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a github.com: https://github.com/axios/axios/releases/tag/v1.20.0