CVE-2026-101901
Last modified
CVE-2026-101901 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse.
Description
Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse. A request uses httpVersion: 2 and the ClientHttp2Session emits an error during session initialization or reuse. The unhandled session error escapes normal Promise rejection handling. The uncaught error can terminate the Node.js process and cause denial of service. This issue is fixed in version 1.20.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| axios | axios | >= 1.13.0, < 1.20.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-101901?
How severe is CVE-2026-101901?
How do I fix CVE-2026-101901?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-101891An improper access control vulnerability in an internal API …9.3
- CVE-2026-101894The decompress package for Node.js extracts archives. Prior …9.1
- CVE-2026-101898Axios is a promise-based HTTP client for the browser and Nod…7
- CVE-2026-1019Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-10190A vulnerability was found in Tenda W12 3.0.0.7(4763). This i…6.5
- CVE-2026-101900Axios is a promise-based HTTP client for the browser and Nod…6.9
- CVE-2026-101902Axios is a promise-based HTTP client for the browser and Nod…6.9
- CVE-2026-101903Axios is a promise-based HTTP client for the browser and Nod…8.2
- CVE-2026-101904Axios is a promise-based HTTP client for the browser and Nod…6.9
- CVE-2026-101905Axios is a promise-based HTTP client for the browser and Nod…7.6
- CVE-2026-101906Axios is a promise-based HTTP client for the browser and Nod…8.2
- CVE-2026-101907Axios is a promise-based HTTP client for the browser and Nod…7
Are you affected by CVE-2026-101901?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
