axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.
CVSS
No CVSS.
References
Configurations
No configuration.
History
02 Aug 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination. |
01 Aug 2026, 13:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-08-01 13:17
Updated : 2026-08-03 17:16
NVD link : CVE-2026-67315
Mitre link : CVE-2026-67315
CVE.ORG link : CVE-2026-67315
JSON object : View
Products Affected
No product.
CWE
CWE-183
Permissive List of Allowed Inputs
