CVE-2020-28168: Axios
Medium severity, CVSS 5.9. EPSS: 2.4% chance of exploitation in the next 30 days.
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
Affected products
- Axios Axios: from 0.19.0, up to and including 0.21.0
- Siemens Sinec Ins: before 1.0 (fixed in 1.0); version 1.0 only
Published 2020-11-06. Last modified 2026-06-17.