axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.
References
| Link | Resource |
|---|---|
| https://github.com/axios/axios/security/advisories/GHSA-f4gw-2p7v-4548 | Exploit Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/axios-before-no-proxy-bypass-via | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-01 13:17
Updated : 2026-09-01 15:40
NVD link : CVE-2026-67315
Mitre link : CVE-2026-67315
CVE.ORG link : CVE-2026-67315
JSON object : View
Products Affected
axios
- axios
CWE
CWE-183
Permissive List of Allowed Inputs
