CyberRota Analysis
AI-GeneratedAxios versions 1.15.0 to 1.20.0 are vulnerable to a denial-of-service attack due to a flaw in the handling of crafted redirect hostnames, which can cause significant backtracking in regular expression processing. This vulnerability can lead to blocking the Node.js event loop, impacting application performance and availability. Organizations using affected versions of Axios should prioritize upgrading to version 1.20.0 or later to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.0 until 1.20.0, Axios shouldBypassProxy applies a quadratic trailing-dot regular expression to redirect hostnames. HTTP_PROXY or HTTPS_PROXY is configured, NO_PROXY or no_proxy is non-empty, redirects are followed, and a crafted redirect Location contains many dots followed by a non-dot character. Hostname.replace(/.+$/, '') backtracks quadratically while processing the crafted redirect hostname. Synchronous regular-expression processing can block the Node.js event loop and cause denial of service. This issue is fixed in version 1.20.0.