CVE-2026-67315: Axios
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.
Affected products
- Axios Axios: from 0.31.0, before 0.33.0 (fixed in 0.33.0); from 1.15.0, before 1.18.0 (fixed in 1.18.0)
Published 2026-08-01. Last modified 2026-09-01.