GitHub Security Advisory (GHSA-f4gw-2p7v-4548)Vendor advisory
https://github.com/axios/axios/security/advisories/GHSA-f4gw-2p7v-4548 CVE-2026-67315
MEDIUM
axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0
Record summary
CVE-2026-67315 has a selected CVSS score of 6.9 (medium).
Description
axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 3, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
axiosBrowse axios / axiosDefault status: unaffected | CVE List | 1.15.0 to < 1.18.0 | affected |
| 1.18.0 | unaffected | ||
| 0.31.0 to < 0.33.0 | affected | ||
| 0.33.0 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-67315 VulnCheck Advisory: axios 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0Third-party advisory
https://www.vulncheck.com/advisories/axios-before-no-proxy-bypass-via