Executive brief
Axios is a widely used library for making web requests in JavaScript applications. A security flaw allows attackers to bypass 'NO_PROXY' settings, which are intended to prevent sensitive internal traffic from being sent through an external proxy server. By using specific local network addresses, an attacker could trick the application into sending internal data to a server they control, potentially exposing private information or internal services.
Technical details
Axios contains an incomplete fix for a previous vulnerability (CVE-2025-62718) in its proxy bypass logic. The library's 'isLoopback' function uses a hardcoded set of addresses (localhost, 127.0.0.1, and ::1) to identify local traffic that should bypass a configured proxy. However, it fails to account for the entire 127.0.0.0/8 IPv4 loopback range defined in RFC 1122. An attacker who can control the request URL can use alternative loopback addresses (e.g., 127.0.0.2) to bypass NO_PROXY rules, causing the request to be forwarded to an attacker-controlled proxy. This issue is fixed in versions 1.15.1 and 0.31.1.
Affected products
- Axios axios <= 1.15.0, <= 0.31.0
Timeline
- 2026-04-24: disclosed
- 2026-04-24: patched
- 2026-04-24: advisory
References
- https://github.com/axios/axios/security/advisories/GHSA-pmwg-cvhr-8vh7
- https://access.redhat.com/errata/RHSA-2026:14937
- https://access.redhat.com/errata/RHSA-2026:16476
- https://access.redhat.com/errata/RHSA-2026:16532
- https://access.redhat.com/errata/RHSA-2026:16534
- https://access.redhat.com/errata/RHSA-2026:16535
- https://access.redhat.com/errata/RHSA-2026:16542