Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-39865

Опубликовано: 08 апр. 2026
Источник: redhat
CVSS3: 5.9

Описание

Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent session closures. The vulnerability exists in the Http2Sessions.getSession() method in lib/adapters/http.js. The session cleanup logic contains a control flow error when removing sessions from the sessions array. This vulnerability is fixed in 1.13.2.

A flaw was found in Axios, a promise-based HTTP client. A malicious server can exploit a state corruption bug within the HTTP/2 session cleanup logic, specifically in the Http2Sessions.getSession() method. By initiating concurrent session closures, the server can trigger a control flow error, leading to a client process crash. This vulnerability results in a Denial of Service (DoS) for the client application.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4axiosFix deferred
Gatekeeper 3redhat-user-workloads/gatekeeper-3-18Fix deferred
Gatekeeper 3redhat-user-workloads/gatekeeper-3-19Fix deferred
Migration Toolkit for Applications 8mta/mta-ui-rhel8Fix deferred
Migration Toolkit for Applications 8mta/mta-ui-rhel9Fix deferred
Migration Toolkit for Applications 8redhat-user-workloads/art-imagesFix deferred
Migration Toolkit for Containersredhat-user-workloads/art-imagesFix deferred
Multicluster Engine for Kubernetesredhat-user-workloads/console-mce-mce-210Fix deferred
Multicluster Engine for Kubernetesredhat-user-workloads/console-mce-mce-211Fix deferred
Multicluster Engine for Kubernetesredhat-user-workloads/console-mce-mce-26Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=2456538axios: Axios: Denial of Service via HTTP/2 session cleanup logic state corruption

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
6 дней назад

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent session closures. The vulnerability exists in the Http2Sessions.getSession() method in lib/adapters/http.js. The session cleanup logic contains a control flow error when removing sessions from the sessions array. This vulnerability is fixed in 1.13.2.

CVSS3: 5.9
nvd
7 дней назад

Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent session closures. The vulnerability exists in the Http2Sessions.getSession() method in lib/adapters/http.js. The session cleanup logic contains a control flow error when removing sessions from the sessions array. This vulnerability is fixed in 1.13.2.

CVSS3: 5.9
debian
7 дней назад

Axios is a promise based HTTP client for the browser and Node.js. Star ...

CVSS3: 5.9
github
7 дней назад

Axios HTTP/2 Session Cleanup State Corruption Vulnerability

5.9 Medium

CVSS3

Уязвимость CVE-2026-39865