Axios HTTP/2 Flaws Enable SSRF Control Bypass and Node.js Denial of Service
Two high-severity vulnerabilities in the Axios HTTP/2 implementation allow for SSRF attacks and denial-of-service conditions in Node.js applications.

The popular JavaScript HTTP client, Axios, has disclosed two critical vulnerabilities affecting its HTTP/2 adapter, potentially exposing Node.js applications to significant risks. The first flaw, identified as CVE-2026-101898, enables Server-Side Request Forgery (SSRF) by allowing attackers to bypass custom DNS lookups or proxy configurations. This bypass occurs when Axios fails to apply caller-supplied configurations, such as explicit proxy settings or environment variable inheritance, before establishing an HTTP/2 connection.
This SSRF vulnerability is particularly concerning for applications that accept user-controlled URLs. Security teams often implement custom DNS resolvers to block access to sensitive internal resources, cloud metadata services, or localhost. However, under the vulnerable HTTP/2 code path, Axios can circumvent these protections and connect directly to restricted destinations. An attacker could exploit this by providing a user-influenced URL to a web service that uses Axios to fetch external content, tricking the application into making requests to unauthorized internal endpoints.
The second vulnerability, tracked as CVE-2026-101901, presents a denial-of-service (DoS) risk for Node.js applications. The issue stems from inadequate error handling during the initialization or reuse of an HTTP/2 client session. If an error occurs within this session, it can escape Axios's standard Promise rejection mechanisms and manifest as an uncaught exception. In Node.js environments, uncaught exceptions typically lead to the termination of the running process, effectively causing a denial of service.
The practical impact of this DoS vulnerability is highest in applications that frequently fetch URLs controlled by attackers, process incoming webhooks, or act as proxies for user-specified hosts. By carefully crafting requests that trigger session initialization errors, an attacker could potentially crash the application, disrupting service availability.
Both vulnerabilities were introduced with the HTTP/2 support in Axios's Node.js HTTP adapter, starting from version 1.13.0. The Axios team has addressed these issues by releasing version 1.20.0, which includes fixes for both CVE-2026-101898 and CVE-2026-101901. Users are strongly advised to upgrade to this latest version immediately.
For organizations unable to upgrade immediately, mitigation strategies include disabling HTTP/2 requests by removing the httpVersion: 2 setting or reverting to HTTP/1.1. Additionally, security teams should review applications that handle user-supplied URLs, validate destination hosts rigorously, enforce egress filtering at the network layer, and monitor outbound connections for any anomalous access to internal or cloud metadata services.
These vulnerabilities highlight the ongoing challenges in securing complex network clients and the importance of robust error handling and configuration management, especially when dealing with newer protocols like HTTP/2. The potential for both data exfiltration via SSRF and service disruption via DoS underscores the need for prompt patching and diligent security practices.