CVE-2026-39865 MEDIUM

CVE-2026-39865: Axios HTTP/2 Session Cleanup State Corruption Vulnerability

Vendor Axios
Product axios
Weakness CWE-400
Published April 8, 2026
Last update April 27, 2026

CVSS base score

5.9/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent session closures. The vulnerability exists in the Http2Sessions.getSession() method in lib/adapters/http.js. The session cleanup logic contains a control flow error when removing sessions from the sessions array. This vulnerability is fixed in 1.13.2.

Key dates

02Disclosure timeline

April 8, 2026 CVE published
April 27, 2026 Record updated