CVE-2026-67315

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.
CVSS

No CVSS.

Configurations

No configuration.

History

02 Aug 2026, 12:16

Type Values Removed Values Added
Summary (en) axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination. (en) axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.

01 Aug 2026, 13:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-08-01 13:17

Updated : 2026-08-03 17:16


NVD link : CVE-2026-67315

Mitre link : CVE-2026-67315

CVE.ORG link : CVE-2026-67315


JSON object : View

Products Affected

No product.

CWE
CWE-183

Permissive List of Allowed Inputs