PT-2026-99949 · Npm · Axios
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Axios versions 1.15.0 through 1.19.x
Description
A denial of service can occur when
HTTP PROXY or HTTPS PROXY is configured, NO PROXY or no proxy is non-empty, and redirects are followed. The issue arises when a crafted redirect Location contains numerous dots followed by a non-dot character. In this scenario, the shouldBypassProxy function uses a quadratic trailing-dot regular expression via Hostname.replace(/.+$/, '') that causes quadratic backtracking. This synchronous processing can block the Node.js event loop, leading to a system crash or unresponsiveness.Recommendations
Update Axios to version 1.20.0.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Axios