AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-101901.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 8.2CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 30, 2026

Disclosure summary

## Summary Axios versions with Node.js HTTP/2 support can terminate the caller’s process when a ClientHttp2Session emits an error event that is not handled by axios. This affects applications that use the Node HTTP adapter with httpVersion: 2. A malicious, unavailable, or non-HTTP/2 endpoint can cause an uncaught exception instead of a normal rejected axios request. ## Impact The impact is denial of service. In affected applications, an attacker who can influence the request destination, or operate the destination server, may be able to crash the Node.js process. This does not affect default HTTP/1.1 usage, browser XHR/fetch adapters, or applications that do not enable axios HTTP/2 support. ## Affected Functionality Affected path: - Node.js HTTP adapter - httpVersion: 2 - HTTP/2 session creation/reuse through Http2Sessions - Network/session failures emitted as ClientHttp2Session error events Caller-controlled http2Options can make the issue easier to trigger, but passing arbitrary attacker input into axios config is caller-controlled behavior and should not be the primary advisory framing. ## Technical Details Http2Sessions.getSession() creates a session with http2.connect(authorit

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-542g-h47m-68v8

Open original source · Updated Sep 30, 2026

Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization

Source severity: HIGH / 8.2

EcosystemPackageAffected rangeFirst patched
npmaxios>= 1.13.0, < 1.20.01.20.0

Original records & references

PUBLISHED 2026-09-30T11:01:07-04:00
MODIFIED 2026-09-30T11:01:08-04:00
INGESTED 2026-10-06T11:43:09-04:00