CVE-2026-101898 - Critical Severity Vulnerability
Vulnerable Library - axios-1.18.1.tgz
Promise based HTTP client for the browser and node.js
Library home page: https://registry.npmjs.org/axios/-/axios-1.18.1.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- chromedriver-149.0.4.tgz (Root Library)
- ❌ axios-1.18.1.tgz (Vulnerable Library)
Found in HEAD commit: 512a308a29ab36c63f1df995feee4c8077a71723
Found in base branch: main
Vulnerability Details
Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup does not consistently apply proxy settings and caller-supplied DNS lookup policy. An HTTPS request uses httpVersion: 2 with explicit config.proxy or environment-derived proxy settings, or relies on caller-supplied config.lookup DNS policy. The HTTP/2 path can connect without the configured proxy behavior or without applying the caller-supplied config.lookup policy before http2.connect(). Requests can bypass the intended proxy route or the caller-supplied DNS resolution policy. This issue is fixed in version 1.20.0.
Publish Date: 2026-09-28
URL: CVE-2026-101898
CVSS 3 Score Details (10.0)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-09-28
Fix Resolution: axios - 1.20.0
CVE-2026-101898 - Critical Severity Vulnerability
Promise based HTTP client for the browser and node.js
Library home page: https://registry.npmjs.org/axios/-/axios-1.18.1.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
Found in HEAD commit: 512a308a29ab36c63f1df995feee4c8077a71723
Found in base branch: main
Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup does not consistently apply proxy settings and caller-supplied DNS lookup policy. An HTTPS request uses httpVersion: 2 with explicit config.proxy or environment-derived proxy settings, or relies on caller-supplied config.lookup DNS policy. The HTTP/2 path can connect without the configured proxy behavior or without applying the caller-supplied config.lookup policy before http2.connect(). Requests can bypass the intended proxy route or the caller-supplied DNS resolution policy. This issue is fixed in version 1.20.0.
Publish Date: 2026-09-28
URL: CVE-2026-101898
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Type: Upgrade version
Release Date: 2026-09-28
Fix Resolution: axios - 1.20.0