Npm · Axios · CVE-2026-101906
**Name of the Vulnerable Software and Affected Versions**
Axios versions 1.15.0 through 1.19.x
**Description**
A denial of service can occur when `HTTP PROXY` or `HTTPS PROXY` is configured, `NO PROXY` or `no proxy` is non-empty, and redirects are followed. The issue arises when a crafted redirect Location contains numerous dots followed by a non-dot character. In this scenario, the `shouldBypassProxy` function uses a quadratic trailing-dot regular expression via `Hostname.replace(/.+$/, '')` that causes quadratic backtracking. This synchronous processing can block the Node.js event loop, leading to a system crash or unresponsiveness.
**Recommendations**
Update Axios to version 1.20.0.