OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-101901

HIGH · CVSS 8.2 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Axios versions 1.13.0 to 1.20.0 are vulnerable due to inadequate error handling in the Http2Sessions during HTTP/2 session initialization or reuse, which can lead to unhandled errors that terminate the Node.js process. This vulnerability poses a high risk of denial of service, making it critical for developers using affected versions in their applications to prioritize upgrading to version 1.20.0 or later. Organizations relying on Axios for HTTP/2 communications should assess their implementations to mitigate potential disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-101901
Severity
HIGH
CVSS
8.2
EPSS
0.38%

Original NVD Description

Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse. A request uses httpVersion: 2 and the ClientHttp2Session emits an error during session initialization or reuse. The unhandled session error escapes normal Promise rejection handling. The uncaught error can terminate the Node.js process and cause denial of service. This issue is fixed in version 1.20.0.