Axios Vulnerability Enables DoS Attacks on Node.js Servers

Axios Vulnerability Enables DoS Attacks on Node.js Servers

First seen 10 Feb 2026, 16:42 UTC GbhackersCybersecuritynewsSecurityboulevard 25.9

Article Content

Browse articles
ThreatCluster

A security vulnerability in Axios, tracked as CVE-2026-25639, has been identified, allowing remote attackers to trigger a Denial-of-Service (DoS) condition that can crash Node.js servers with a single malicious request. The flaw is located in the mergeConfig function, which merges configuration objects, affecting numerous applications relying on this popular HTTP client library.

Timeline

2026-02-09
CVE-2026-25639 published
2026-02-10
Axios vulnerability reported by cybersecurity news outlets