PT-2026-99949 · Npm · Axios

·

CVE-2026-101906

·

Published

2026-08-12

·

Updated

2026-09-30

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions Axios versions 1.15.0 through 1.19.x
Description A denial of service can occur when HTTP PROXY or HTTPS PROXY is configured, NO PROXY or no proxy is non-empty, and redirects are followed. The issue arises when a crafted redirect Location contains numerous dots followed by a non-dot character. In this scenario, the shouldBypassProxy function uses a quadratic trailing-dot regular expression via Hostname.replace(/.+$/, '') that causes quadratic backtracking. This synchronous processing can block the Node.js event loop, leading to a system crash or unresponsiveness.
Recommendations Update Axios to version 1.20.0.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15726
CVE-2026-101906
GHSA-MGHH-PGCX-3JJJ

Affected Products

Axios