Junglewise Threat Intelligence

Axios NO_PROXY bypass via 0.0.0.0 local address

Severity: low · CVSS 3.1 · Published 2026-08-01

Technologies: Axios. Vendors: Axios.

Executive brief

Axios is a popular HTTP client library used by Node.js applications to make web requests. The library can be configured to route certain requests through a proxy server while bypassing the proxy for local addresses via NO_PROXY environment variables. A flaw in versions 1.15.0 through 1.17.x fails to recognize 0.0.0.0 as a local address, allowing attackers who control request URLs to bypass proxy filtering and potentially expose local services running on the machine.

Technical details

The vulnerability exists in lib/helpers/shouldBypassProxy.js, where the isLoopback() function fails to include 0.0.0.0 in its loopback address recognition logic. While the function correctly identifies 127.0.0.0/8 and ::1 as loopback addresses, it omits 0.0.0.0 (the IPv4 unspecified address), which resolves to localhost on Linux and macOS. When a NO_PROXY policy is set (e.g., NO_PROXY=localhost,127.0.0.1,::1), a request to http://0.0.0.0:<port>/ is incorrectly routed through the configured proxy instead of being bypassed. This affects Node.js applications using the HTTP adapter with environment-derived proxy settings. An attacker who can influence the axios request URL or redirect target can exploit this to bypass proxy-based SSRF protections. HTTPS requests are partially mitigated due to CONNECT tunneling. Patched versions 1.18.0 and 0.33.0 and later include 0.0.0.0 in the loopback check.

Affected products

  • Axios axios 1.15.0 to 1.17.x; 0.31.0 to 0.32.x

Timeline

  • 2026-07-06: disclosed: Original advisory GHSA-f4gw-2p7v-4548 published
  • 2026-08-01: other: Duplicate advisory GHSA-6hqm-hm2v-3p2p published
  • 2026-09-01: other: Duplicate advisory withdrawn

References

Related threats