CVE-2026-39865: Axios HTTP/2 Session Cleanup State Corruption Vulnerability
(updated )
Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent session closures. This denial-of-service vulnerability affects axios versions prior to 1.13.2 when HTTP/2 is enabled.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-39865 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →