VYPR
High severity7.5OSV Advisory· Published Aug 1, 2026· Updated Sep 1, 2026

CVE-2026-67315

CVE-2026-67315

Description

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
axiosnpm
>= 1.15.0, < 1.18.01.18.0
axiosnpm
>= 0.31.0, < 0.33.00.33.0

Affected products

59

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.