CVE-2026-101903: Axios
High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.
Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash characters on both sides of the media-type separator. An application passes an attacker-controlled malformed data URL containing many slash characters and no comma. the JavaScript regular-expression engine explores many separator placements before rejecting the URL. Synchronous excessive backtracking can block the Node.js event loop and cause denial of service. The affected identifiers are fromDataURI, DATA_URL_PATTERN, data:. This issue is fixed in version 1.20.0.
Affected products
- Axios Axios: from 1.16.1, before 1.20.0 (fixed in 1.20.0)
Published 2026-09-28. Last modified 2026-09-30.