Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization
Published Sep 28, 2026
8.2
HIGHCVSS 4.0
EPSS 0.38%
Description
Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse. A request uses httpVersion: 2 and the ClientHttp2Session emits an error during session initialization or reuse. The unhandled session error escapes normal Promise rejection handling. The uncaught error can terminate the Node.js process and cause denial of service. This issue is fixed in version 1.20.0.
Affected products
-
- Version >= 1.13.0, < 1.20.0StatusaffectedConstraints-
- Version
No data.
No data.
Red Hat Hardened Images
grafana12.4
Affected
Red Hat Hardened Images
grafana13.1
Affected
Red Hat Hardened Images
grafana13.2
Affected
Red Hat Hardened Images
jaeger
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | grafana12.4 | Affected | n/a |
| Red Hat Hardened Images | grafana13.1 | Affected | n/a |
| Red Hat Hardened Images | grafana13.2 | Affected | n/a |
| Red Hat Hardened Images | jaeger | Not affected | n/a |
axios
npm
Introduced 1.13.0 Fixed 1.20.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | axios | 1.13.0 | 1.20.0 |
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Oct 1, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.38% (0.00384) | 30.08th | v5 (v2026.06.15) |
| Oct 1, 2026 | 0.38% (0.00384) | 29.99th | v5 (v2026.06.15) |
References (9)
- https://access.redhat.com/security/cve/CVE-2026-101901 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2542577 Issue Tracking
- https://github.com/advisories/GHSA-542g-h47m-68v8 Advisory
- https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a x_refsource_MISC
- https://github.com/axios/axios/pull/11141 x_refsource_MISC
- https://github.com/axios/axios/releases/tag/v1.20.0 x_refsource_MISC
- https://github.com/axios/axios/security/advisories/GHSA-542g-h47m-68v8 exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-101901
- https://www.cve.org/CVERecord?id=CVE-2026-101901
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-101901 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2542577 | Issue Tracking | |
| https://github.com/advisories/GHSA-542g-h47m-68v8 | Advisory | |
| https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a | x_refsource_MISC | |
| https://github.com/axios/axios/pull/11141 | x_refsource_MISC | |
| https://github.com/axios/axios/releases/tag/v1.20.0 | x_refsource_MISC | |
| https://github.com/axios/axios/security/advisories/GHSA-542g-h47m-68v8 | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-101901 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-101901 |
Change history (0)
No recorded changes yet.