Disclosure summary
## Summary Axios for Node.js does not apply configured DNS lookup or proxy controls when a request uses `httpVersion: 2`. The HTTP/1 adapter path wraps and forwards `config.lookup`, builds normal request options, and applies proxy routing through `setProxy()`. The HTTP/2 path builds a session with `http2.connect()` using only `options.http2Options`, which drops the top-level `lookup`, `agent`, and proxy state. Applications are affected when they allow a user to influence request destinations, enable axios HTTP/2, and rely on axios `lookup` or proxy routing to prevent SSRF or enforce outbound network policy. ## Impact In affected server-side deployments, an attacker can cause axios to connect directly to destinations that the configured resolver or proxy would have rejected. Depending on reachable services, this can expose cloud metadata, internal service responses, or allow state-changing requests to internal systems. This is not an unconditional SSRF in every axios deployment. It requires `httpVersion: 2` and an application-level trust boundary where user-influenced URLs are constrained by `lookup` or proxy policy. ## Affected Functionality Affected: - Node.js HTTP adapter with `h
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-3pq3-5fj3-cg6v
Open original source · Updated Sep 30, 2026
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
Source severity: HIGH / 7
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | axios | >= 1.13.0, < 1.20.0 | 1.20.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-30T11:02:14-04:00
MODIFIED 2026-09-30T11:02:15-04:00
INGESTED 2026-10-06T11:43:09-04:00