Axios maintainers have disclosed several high-severity security vulnerabilities that could allow attackers to bypass proxy and DNS controls in server-side applications, potentially enabling server-side request forgery (SSRF) against internal services and cloud metadata endpoints. The most critical issue, tracked as GHSA-3pq3-5fj3-cg6v, affects Axios’s HTTP/2 request path. This vulnerability arises because the HTTP/2 adapter establishes sessions […]
Read the original article:
