Resource exhaustion in axios - CVE-2026-39865
Published: April 8, 2026
Vulnerability identifier: #VU125102
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-39865
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the HTTP/2 session cleanup logic contains a state corruption bug. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
axios
PowerVC
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Fedora
pgadmin4
nextcloud
PowerVC
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Fedora
pgadmin4
nextcloud
How to mitigate CVE-2026-39865
Install updates from vendor's website.
axios - update to 1.13.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
pgadmin4 - addressed in versions 9.14-2.fc42, 9.14-2.fc43, 9.14-2.fc44, 9.14-3.fc42, 9.14-3.fc43, 9.14-3.fc44
App Connect Enterprise Certified Container - addressed in versions 12.0.20, 12.21.0
nextcloud - addressed in versions 33.0.3-1.el10_2, 33.0.3-1.el10_3, 33.0.3-1.fc42, 33.0.3-1.fc43, 33.0.3-1.fc44
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
pgadmin4 - addressed in versions 9.14-2.fc42, 9.14-2.fc43, 9.14-2.fc44, 9.14-3.fc42, 9.14-3.fc43, 9.14-3.fc44
App Connect Enterprise Certified Container - addressed in versions 12.0.20, 12.21.0
nextcloud - addressed in versions 33.0.3-1.el10_2, 33.0.3-1.el10_3, 33.0.3-1.fc42, 33.0.3-1.fc43, 33.0.3-1.fc44
External References
Related Security Bulletins
- Denial of service in Axios
- Fedora 44 update for pgadmin4
- Fedora 43 update for pgadmin4
- Fedora 42 update for pgadmin4
- IBM App Connect Enterprise Certified Container update for Axios
- IBM PowerVC update for Axios
- Fedora 43 update for pgadmin4
- Fedora 42 update for pgadmin4
- Fedora 44 update for pgadmin4
- IBM Watson Discovery Cartridge update for Axios
- Fedora 44 update for nextcloud
- Fedora 43 update for nextcloud
- Fedora EPEL 10.3 update for nextcloud
- Fedora EPEL 10.2 update for nextcloud
- Fedora 42 update for nextcloud