PT-2026-99938 · Npm · Axios
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Axios versions 1.13.0 through 1.19.x
Description
HTTP/2 request setup fails to consistently apply proxy settings and caller-supplied DNS lookup policies. When an HTTPS request is configured with
httpVersion: 2 and uses config.proxy or environment-derived proxy settings, or relies on a config.lookup DNS policy, the HTTP/2 path may connect without applying these configurations before calling http2.connect(). This allows requests to bypass the intended proxy route or the specified DNS resolution policy.Recommendations
Update to version 1.20.0.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Axios