CVE-2026-101901

Source
https://cve.org/CVERecord?id=CVE-2026-101901
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101901.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-101901
Aliases
Downstream
Published
2026-09-28T17:16:21Z
Modified
2026-09-30T03:47:02Z
Severity
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization
Details

Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse. A request uses httpVersion: 2 and the ClientHttp2Session emits an error during session initialization or reuse. The unhandled session error escapes normal Promise rejection handling. The uncaught error can terminate the Node.js process and cause denial of service. This issue is fixed in version 1.20.0.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-400"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101901.json"
}
References

Affected packages

Git / github.com/axios/axios

Affected ranges

Type
GIT
Repo
https://github.com/axios/axios
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "1.13.0"
        },
        {
            "fixed":  "1.20.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.13.0
v1.13.1
v1.13.2
v1.13.3
v1.13.4
v1.13.5
v1.13.6
v1.14.0
v1.15.0
v1.15.1
v1.15.2
v1.16.0
v1.16.1
v1.17.0
v1.18.0
v1.18.1
v1.19.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101901.json"