Axios HTTP/2 Flaws Enable SSRF Control Bypass and Node.js Denial of Service

Axios has disclosed two high-severity vulnerabilities in its HTTP/2 implementation that could allow attackers to bypass outbound network controls or crash vulnerable Node.js applications. The flaws affect Axios versions 1.13.0 through 1.19.x and have been fixed in version 1.20.0 The first issue, tracked as GHSA-3pq3-5fj3-cg6v and CVE-2026-101898, affects Axios applications that use HTTP/2 requests alongside […]

This article has been indexed from Cyber Security News

Read the original article: