CVE-2026-67315CWE-183

CVE-2026-67315

High · published August 1, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
25.7
In the wild
Unconfirmed
What it is

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00331 · 25.7th percentile
Weakness
CWE-183 · Permissive List of Allowed Inputs
Published
2026-08-01T17:17Z
Affected products (2)
ProductVersionsFixed in
axios/axios≥ 0.31.0, < 0.33.00.33.0
axios/axios≥ 1.15.0, < 1.18.01.18.0
References (2)
EPSS history
Timeline
  • 01 AUG 12:22Z
    axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0
    cvelistv5