CVE-2026-101903High· 8.2▾ MidnightPoC availableAxios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash characters on both sides of the media-type separator. An application passes an attacker-controlled m…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 45.1 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash characters on both sides of the media-type separator. An application passes an attacker-controlled malformed data URL containing many slash characters and no comma. the JavaScript regular-expression engine explores many separator placements before rejecting the URL. Synchronous excessive backtracking can block the Node.js event loop and cause denial of service. The affected identifiers are fromDataURI, DATA_URL_PATTERN, data:. This issue is fixed in version 1.20.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-101906High· 8.2Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101907High· 7.0Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101908Medium· 6.9Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101904Medium· 6.9Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101900Medium· 6.9Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101898High· 7.0Axios is a promise-based HTTP client for the browser and Node.js