Unrated severityOSV Advisory· Published Aug 2, 2026
Debian node-axios: axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback addr…
CVE-2026-67315
Description
axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.
Affected products
3- Range: 1.15.0 <= v < 1.18.0
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.