NO_PROXY Bypass Vulnerability in Axios by Axios
CVE-2026-67315

6.9MEDIUM

Key Information:

Vendor

AxiOS

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-67315?

A security flaw in Axios versions prior to 1.18.0 allows the library to mistakenly interpret 0.0.0.0 as a loopback address in the shouldBypassProxy.js file. This oversight enables attackers to circumvent the NO_PROXY settings, directing requests through configured proxies that may inadvertently expose sensitive local services. By leveraging this vulnerability, malicious actors can manipulate network traffic and potentially compromise the confidentiality and integrity of sensitive data.

Affected Version(s)

axios 1.15.0 < 1.18.0

axios 0.31.0 < 0.33.0

axios 1.18.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jayant-eai
.