VYPR
Unrated severityOSV Advisory· Published Aug 2, 2026

Debian node-axios: axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback addr…

CVE-2026-67315

Description

axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.

Affected products

3
  • Axios/AxiosOSV2 versions
    v1.17.0, v1.16.1, v0.32.0, …+ 1 more
    • (no CPE)range: v1.17.0, v1.16.1, v0.32.0, …
    • (no CPE)range: 1.15.0 <= v < 1.18.0
  • Debian/node-axiosllm-create
    Range: 1.15.0 <= v < 1.18.0

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.

CVE-2026-67315 · VYPR