Looking for the vulnerability index of Invicti's legacy products?
axios : Inefficient Regular Expression Complexity Vulnerability (CVE-2026-101903) - Vulnerability Database

axios : Inefficient Regular Expression Complexity Vulnerability (CVE-2026-101903)

Description

Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash characters on both sides of the media-type separator. An application passes an attacker-controlled malformed data URL containing many slash characters and no comma. the JavaScript regular-expression engine explores many separator placements before rejecting the URL. Synchronous excessive backtracking can block the Node.js event loop and cause denial of service.

Related Vulnerabilities