# CVE-2026-39865

## Summary

- **CVE ID:** CVE-2026-39865
- **Severity:** MEDIUM
- **CVSS Score:** 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-400, CWE-662
- **Published:** Apr 8, 2026
- **Last Modified:** Apr 27, 2026

## Description

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent session closures. The vulnerability exists in the Http2Sessions.getSession() method in lib/adapters/http.js. The session cleanup logic contains a control flow error when removing sessions from the sessions array. This vulnerability is fixed in 1.13.2.

## Affected Products

- axios — axios (< 1.13.2)
- axios — axios (>= 1.13.0, < 1.13.2)

## References

- [CNA](https://github.com/axios/axios/security/advisories/GHSA-qj83-cq47-w5f8)
- [CNA](https://github.com/axios/axios/commit/0588880ac7ddba7594ef179930493884b7e90bf5)
- [CNA](https://github.com/axios/axios/releases/tag/v1.13.2)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.73%
- **EPSS Percentile:** 52.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._