Axios disclosed two high-severity HTTP/2 flaws that could bypass network controls or crash Node.js applications.