๐Ÿ” CVE Alert

CVE-2026-67315

UNKNOWN 0.0

axios 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.

CWE CWE-183
Vendor axios
Product axios
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for axios axios

Be the first to know when new unknown vulnerabilities affecting axios axios are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

axios / axios
1.15.0 < 1.18.0
axios / axios
0.31.0 < 0.33.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/axios/axios/security/advisories/GHSA-f4gw-2p7v-4548 vulncheck.com: https://www.vulncheck.com/advisories/axios-before-no-proxy-bypass-via

Credits

๐Ÿ” jayant-eai