
🔴 Axios (Nodejs), ReDoS, #CVE-2026-101903 (High) -DC-Sep2026-2672 https://dailycve.com/axios-nodejs-redos-cve-2026-101903-high-dc-sep2026-2672/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash characters on both sides of the media-type separator. An application passes an attacker-controlled malformed data URL containing many slash characters and no comma. the JavaScript regular-expression engine explores many separator placements before rejecting the URL. Synchronous excessive backtracking can block the Node.js event loop and cause denial of service. The affected identifiers are fromDataURI, DATA_URL_PATTERN, data:. This issue is fixed in version 1.20.0.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🔴 Axios (Nodejs), ReDoS, #CVE-2026-101903 (High) -DC-Sep2026-2672 https://dailycve.com/axios-nodejs-redos-cve-2026-101903-high-dc-sep2026-2672/