PT-2026-99938 · Npm · Axios

·

CVE-2026-101898

·

Published

2026-08-12

·

Updated

2026-09-30

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Axios versions 1.13.0 through 1.19.x
Description HTTP/2 request setup fails to consistently apply proxy settings and caller-supplied DNS lookup policies. When an HTTPS request is configured with httpVersion: 2 and uses config.proxy or environment-derived proxy settings, or relies on a config.lookup DNS policy, the HTTP/2 path may connect without applying these configurations before calling http2.connect(). This allows requests to bypass the intended proxy route or the specified DNS resolution policy.
Recommendations Update to version 1.20.0.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15724
CVE-2026-101898
GHSA-3PQ3-5FJ3-CG6V

Affected Products

Axios