{"id":"CVE-2026-101898","published":"2026-09-28T18:17:17.860","lastModified":"2026-09-28T18:17:17.860","description":"Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup does not consistently apply proxy settings and caller-supplied DNS lookup policy. An HTTPS request uses httpVersion: 2 with explicit config.proxy or environment-derived proxy settings, or relies on caller-supplied config.lookup DNS policy. The HTTP/2 path can connect without the configured proxy behavior or without applying the caller-supplied config.lookup policy before http2.connect(). Requests can bypass the intended proxy route or the caller-supplied DNS resolution policy. This issue is fixed in version 1.20.0.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-918"],"vendors":[],"products":[],"references":[{"url":"https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","tags":[]},{"url":"https://github.com/axios/axios/pull/11141","tags":[]},{"url":"https://github.com/axios/axios/releases/tag/v1.20.0","tags":[]},{"url":"https://github.com/axios/axios/security/advisories/GHSA-3pq3-5fj3-cg6v","tags":[]},{"url":"https://github.com/axios/axios/security/advisories/GHSA-3pq3-5fj3-cg6v","tags":[]}],"exploitRefs":[{"url":"https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a","tags":[]},{"url":"https://github.com/axios/axios/pull/11141","tags":[]},{"url":"https://github.com/axios/axios/releases/tag/v1.20.0","tags":[]},{"url":"https://github.com/axios/axios/security/advisories/GHSA-3pq3-5fj3-cg6v","tags":[]},{"url":"https://github.com/axios/axios/security/advisories/GHSA-3pq3-5fj3-cg6v","tags":[]}],"hasPoc":true,"ai":null}