CVE-2026-101898 | Axios up to 1.19.x HTTP/2 Request Setup http2.connect proxy/lookup access control

SecurityVulns

A vulnerability was found in Axios up to 1.19.x and classified as critical. Affected by this vulnerability is the function http2.connect of the component HTTP2 Request Setup. The manipulation of the argument proxy/lookup results in improper access controls.

This vulnerability is cataloged as CVE-2026-101898. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More