AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-101903.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 8.2CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 30, 2026

Disclosure summary

## Summary Axios for Node.js parses `data:` URLs in `lib/helpers/fromDataURI.js`. The current RFC-2397 parser uses a regular expression whose media type groups allow `/` inside both sides of the `type/subtype` match. A malformed `data:` URL containing many slashes and no comma forces the JavaScript regex engine to try many possible placements for the separator before failing. Applications are affected when they pass untrusted URL strings to axios and do not reject or constrain `data:` URLs before axios parses them. ## Impact An attacker can make the Node.js event loop spend significant synchronous CPU time parsing a single malformed URL. In a server that accepts a URL from an HTTP request and calls `axios.get(url)`, this can block unrelated requests and health checks until parsing completes. The issue is availability-only. It does not disclose data or modify requests. ## Affected Functionality Affected: - Node.js HTTP adapter data URL handling. - `axios.get()` or equivalent calls where `config.url` has the `data:` protocol. Not affected: - Browser fetch/XHR URL handling. - Node requests where the application rejects `data:` URLs before calling axios. - Older checked `0.x` data URL

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-c29m-xwm3-cm6r

Open original source · Updated Sep 30, 2026

Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)

Source severity: HIGH / 8.2

EcosystemPackageAffected rangeFirst patched
npmaxios>= 1.16.1, < 1.20.01.20.0

Original records & references

PUBLISHED 2026-09-30T11:03:21-04:00
MODIFIED 2026-09-30T11:03:23-04:00
INGESTED 2026-10-06T11:43:09-04:00