High severityNVD Advisory· Published Mar 7, 2025· Updated Mar 7, 2025
Possible SSRF and Credential Leakage via Absolute URL in axios Requests
CVE-2025-27152
Description
axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impacts both server-side and client-side usage of axios. This issue is fixed in 1.8.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
axiosnpm | >= 1.0.0, < 1.8.2 | 1.8.2 |
axiosnpm | < 0.30.0 | 0.30.0 |
Affected products
110- osv-coords109 versionspkg:apk/chainguard/airflow-2pkg:apk/chainguard/airflow-2-compatpkg:apk/chainguard/airflow-2-iamguarded-compatpkg:apk/chainguard/jitsucom-jitsupkg:apk/chainguard/jitsucom-jitsu-consolepkg:apk/chainguard/jitsucom-jitsu-rotorpkg:apk/chainguard/kibana-7pkg:apk/chainguard/kubeflow-centraldashboardpkg:apk/chainguard/kubeflow-pipelinespkg:apk/chainguard/kubeflow-pipelines-apiserverpkg:apk/chainguard/kubeflow-pipelines-cache-deployerpkg:apk/chainguard/kubeflow-pipelines-cache-deployer-compatpkg:apk/chainguard/kubeflow-pipelines-cache_serverpkg:apk/chainguard/kubeflow-pipelines-frontendpkg:apk/chainguard/kubeflow-pipelines-metadata-envoy-configpkg:apk/chainguard/kubeflow-pipelines-metadata-writerpkg:apk/chainguard/kubeflow-pipelines-metadata-writer-compatpkg:apk/chainguard/kubeflow-pipelines-persistence_agentpkg:apk/chainguard/kubeflow-pipelines-scheduledworkflowpkg:apk/chainguard/kubeflow-pipelines-viewer-crd-controllerpkg:apk/chainguard/lernapkg:apk/chainguard/opensearch-dashboards-2pkg:apk/chainguard/opensearch-dashboards-2-alerting-dashboards-pluginpkg:apk/chainguard/opensearch-dashboards-2-anomaly-detection-dashboards-pluginpkg:apk/chainguard/opensearch-dashboards-2-configpkg:apk/chainguard/opensearch-dashboards-2-dashboards-mapspkg:apk/chainguard/opensearch-dashboards-2-dashboards-notificationspkg:apk/chainguard/opensearch-dashboards-2-dashboards-observabilitypkg:apk/chainguard/opensearch-dashboards-2-dashboards-query-workbenchpkg:apk/chainguard/opensearch-dashboards-2-dashboards-reportingpkg:apk/chainguard/opensearch-dashboards-2-dashboards-search-relevancepkg:apk/chainguard/opensearch-dashboards-2-dashboards-visualizationspkg:apk/chainguard/opensearch-dashboards-2-fipspkg:apk/chainguard/opensearch-dashboards-2-fips-alerting-dashboards-pluginpkg:apk/chainguard/opensearch-dashboards-2-fips-anomaly-detection-dashboards-pluginpkg:apk/chainguard/opensearch-dashboards-2-fips-configpkg:apk/chainguard/opensearch-dashboards-2-fips-dashboards-mapspkg:apk/chainguard/opensearch-dashboards-2-fips-dashboards-notificationspkg:apk/chainguard/opensearch-dashboards-2-fips-dashboards-observabilitypkg:apk/chainguard/opensearch-dashboards-2-fips-dashboards-query-workbenchpkg:apk/chainguard/opensearch-dashboards-2-fips-dashboards-reportingpkg:apk/chainguard/opensearch-dashboards-2-fips-dashboards-search-relevancepkg:apk/chainguard/opensearch-dashboards-2-fips-dashboards-visualizationspkg:apk/chainguard/opensearch-dashboards-2-fips-index-management-dashboards-pluginpkg:apk/chainguard/opensearch-dashboards-2-fips-ml-commons-dashboardspkg:apk/chainguard/opensearch-dashboards-2-fips-security-analytics-dashboards-pluginpkg:apk/chainguard/opensearch-dashboards-2-fips-security-dashboards-pluginpkg:apk/chainguard/opensearch-dashboards-2-index-management-dashboards-pluginpkg:apk/chainguard/opensearch-dashboards-2-ml-commons-dashboardspkg:apk/chainguard/opensearch-dashboards-2-security-analytics-dashboards-pluginpkg:apk/chainguard/opensearch-dashboards-2-security-dashboards-pluginpkg:apk/chainguard/prismpkg:apk/chainguard/tileserver-glpkg:apk/chainguard/tileserver-gl-compatpkg:apk/chainguard/tileserver-gl-fipspkg:apk/chainguard/tileserver-gl-fips-compatpkg:apk/wolfi/jitsucom-jitsupkg:apk/wolfi/jitsucom-jitsu-consolepkg:apk/wolfi/jitsucom-jitsu-rotorpkg:apk/wolfi/kubeflow-centraldashboardpkg:apk/wolfi/kubeflow-pipelinespkg:apk/wolfi/kubeflow-pipelines-apiserverpkg:apk/wolfi/kubeflow-pipelines-cache-deployerpkg:apk/wolfi/kubeflow-pipelines-cache-deployer-compatpkg:apk/wolfi/kubeflow-pipelines-cache_serverpkg:apk/wolfi/kubeflow-pipelines-frontendpkg:apk/wolfi/kubeflow-pipelines-metadata-envoy-configpkg:apk/wolfi/kubeflow-pipelines-metadata-writerpkg:apk/wolfi/kubeflow-pipelines-metadata-writer-compatpkg:apk/wolfi/kubeflow-pipelines-persistence_agentpkg:apk/wolfi/kubeflow-pipelines-scheduledworkflowpkg:apk/wolfi/kubeflow-pipelines-viewer-crd-controllerpkg:apk/wolfi/lernapkg:apk/wolfi/opensearch-dashboards-2pkg:apk/wolfi/opensearch-dashboards-2-alerting-dashboards-pluginpkg:apk/wolfi/opensearch-dashboards-2-anomaly-detection-dashboards-pluginpkg:apk/wolfi/opensearch-dashboards-2-configpkg:apk/wolfi/opensearch-dashboards-2-dashboards-mapspkg:apk/wolfi/opensearch-dashboards-2-dashboards-notificationspkg:apk/wolfi/opensearch-dashboards-2-dashboards-observabilitypkg:apk/wolfi/opensearch-dashboards-2-dashboards-query-workbenchpkg:apk/wolfi/opensearch-dashboards-2-dashboards-reportingpkg:apk/wolfi/opensearch-dashboards-2-dashboards-search-relevancepkg:apk/wolfi/opensearch-dashboards-2-dashboards-visualizationspkg:apk/wolfi/opensearch-dashboards-2-index-management-dashboards-pluginpkg:apk/wolfi/opensearch-dashboards-2-ml-commons-dashboardspkg:apk/wolfi/opensearch-dashboards-2-security-analytics-dashboards-pluginpkg:apk/wolfi/opensearch-dashboards-2-security-dashboards-pluginpkg:apk/wolfi/prismpkg:apk/wolfi/tileserver-glpkg:apk/wolfi/tileserver-gl-compatpkg:npm/axiospkg:rpm/opensuse/pgadmin4&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/velociraptor&distro=openSUSE%20Tumbleweedpkg:rpm/suse/pgadmin4&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/pgadmin4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/pgadmin4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/pgadmin4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/pgadmin4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOSpkg:rpm/suse/pgadmin4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSSpkg:rpm/suse/pgadmin4&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%203%2015%20SP6pkg:rpm/suse/pgadmin4&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/pgadmin4&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/pgadmin4&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSSpkg:rpm/suse/pgadmin4&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/pgadmin4&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/pgadmin4&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5pkg:rpm/suse/pgadmin4&distro=SUSE%20Manager%20Proxy%204.3pkg:rpm/suse/pgadmin4&distro=SUSE%20Manager%20Server%204.3
< 2.11.0-r15+ 108 more
- (no CPE)range: < 2.11.0-r15
- (no CPE)range: < 2.11.0-r15
- (no CPE)range: < 2.11.0-r15
- (no CPE)range: < 2.8.6-r2
- (no CPE)range: < 2.8.6-r2
- (no CPE)range: < 2.8.6-r2
- (no CPE)range: < 7.17.29-r5
- (no CPE)range: < 1.9.2-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 8.2.1-r1
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.2-r4
- (no CPE)range: < 2.19.2-r4
- (no CPE)range: < 2.19.2-r4
- (no CPE)range: < 2.19.2-r4
- (no CPE)range: < 2.19.2-r4
- (no CPE)range: < 2.19.2-r4
- (no CPE)range: < 2.19.2-r4
- (no CPE)range: < 2.19.2-r4
- (no CPE)range: < 2.19.2-r4
- (no CPE)range: < 2.19.2-r4
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.2-r4
- (no CPE)range: < 2.19.2-r4
- (no CPE)range: < 2.19.2-r4
- (no CPE)range: < 2.19.2-r4
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 5.12.1-r4
- (no CPE)range: < 5.1.3-r2
- (no CPE)range: < 5.1.3-r2
- (no CPE)range: < 5.1.3-r2
- (no CPE)range: < 5.1.3-r2
- (no CPE)range: < 2.8.6-r2
- (no CPE)range: < 2.8.6-r2
- (no CPE)range: < 2.8.6-r2
- (no CPE)range: < 1.9.2-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 2.4.0-r5
- (no CPE)range: < 8.2.1-r1
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 2.19.4-r0
- (no CPE)range: < 5.12.1-r4
- (no CPE)range: < 5.1.3-r2
- (no CPE)range: < 5.1.3-r2
- (no CPE)range: >= 1.0.0, < 1.8.2
- (no CPE)range: < 8.5-150600.3.9.1
- (no CPE)range: < 0.7.0.4.git163.87ee3570-1.1
- (no CPE)range: < 4.30-150300.3.18.1
- (no CPE)range: < 4.30-150300.3.18.1
- (no CPE)range: < 4.30-150300.3.18.1
- (no CPE)range: < 4.30-150300.3.18.1
- (no CPE)range: < 4.30-150300.3.18.1
- (no CPE)range: < 4.30-150300.3.18.1
- (no CPE)range: < 8.5-150600.3.9.1
- (no CPE)range: < 4.30-150300.3.18.1
- (no CPE)range: < 4.30-150300.3.18.1
- (no CPE)range: < 4.30-150300.3.18.1
- (no CPE)range: < 4.30-150300.3.18.1
- (no CPE)range: < 4.30-150300.3.18.1
- (no CPE)range: < 4.30-150300.3.18.1
- (no CPE)range: < 4.30-150300.3.18.1
- (no CPE)range: < 4.30-150300.3.18.1
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-jr5f-v2jv-69x6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-27152ghsaADVISORY
- github.com/axios/axios/commit/02c3c69ced0f8fd86407c23203835892313d7fdeghsaWEB
- github.com/axios/axios/commit/fb8eec214ce7744b5ca787f2c3b8339b2f54b00fghsaWEB
- github.com/axios/axios/issues/6463ghsax_refsource_MISCWEB
- github.com/axios/axios/pull/6829ghsaWEB
- github.com/axios/axios/releases/tag/v1.8.2ghsaWEB
- github.com/axios/axios/security/advisories/GHSA-jr5f-v2jv-69x6ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.