Executive brief
Axios is a popular Node.js HTTP client library used to make web requests in server-side applications. When applications configure HTTP proxies with NO_PROXY rules to exclude local traffic (e.g., localhost, 127.0.0.1), axios incorrectly routes requests to 0.0.0.0 through the proxy instead of bypassing it. An attacker who controls a URL or redirect target in an axios request can exploit this to expose local services or cause the proxy to access internal systems, potentially leading to data exposure or SSRF attacks.
Technical details
This is an incomplete loopback-address validation vulnerability (CWE-183) in the isLoopback() function within lib/helpers/shouldBypassProxy.js. The vulnerable component incorrectly identifies which addresses should bypass proxy rules; it recognizes localhost, 127.0.0.0/8, and ::1 as loopback, but fails to include 0.0.0.0 (the IPv4 unspecified address). In Node.js, 0.0.0.0 routes to the local machine, but the WHATWG URL parser does not normalize it to 127.0.0.1 as it does with octal (0177.0.0.1), decimal (2130706433), or hexadecimal (0x7f000001) loopback forms. The attack requires an attacker to influence the request URL or redirect target and relies on the configured proxy being able to reach or relay requests to 0.0.0.0. Axios 1.18.0 and 0.33.0 patch the vulnerability by including 0.0.0.0 in the loopback address check. This affects only the Node.js HTTP adapter; browser, React Native, XHR, and fetch adapters are not impacted.
Affected products
- axios axios >=1.15.0, <1.18.0; >=0.31.0, <0.33.0
Timeline
- 2026-07-06: disclosed: Original advisory GHSA-f4gw-2p7v-4548 published
- 2026-08-01: advisory: Duplicate advisory GHSA-6hqm-hm2v-3p2p published; NVD entry added for CVE-2026-67315
- 2026-08-01: patched: Patches available: axios 1.18.0 and 0.33.0
- 2026-09-01: other: GHSA-6hqm-hm2v-3p2p withdrawn as duplicate of GHSA-f4gw-2p7v-4548