CVE-2025-62718

critical
Published 2026-04-09 · Modified 2026-05-08
CVSS v3
9.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS v2
VIR risk
9.9

Description

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the configured proxy. This goes against what developers expect and lets attackers force requests through a proxy, even if NO_PROXY is set up to protect loopback or internal services. This issue leads to the possibility of proxy bypass and SSRF vulnerabilities allowing attackers to reach sensitive loopback or internal services despite the configured protections. This vulnerability is fixed in 1.15.0 and 0.31.0.

Predictions

Exploit likelihood
98%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-62718

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2025-62718.html

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/axios/axios/security/advisories/GHSA-3p68-rc4w-qgx5

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/axios/axios/releases/tag/v1.15.0

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/axios/axios/releases/tag/v0.31.0

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/axios/axios/pull/10661

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/axios/axios/commit/fb3befb6daac6cad26b2e54094d0f2d9e47f24df

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/axios/axios/commit/03cdfc99e8db32a390e12128208b6778492cee9c

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyfixed1.15.0-1
debian debiansidfixed1.15.0-1
debian debiantrixieaffected

Package impact

EcosystemPackageVulnerableFixed
npm npmaxios>=1.0.0,<1.15.01.15.0
npm npmaxios<0.31.00.31.0

Application impact

VendorProductVersionsFixed
axiosaxios{"endExcluding":"0.31.0"}0.31.0

References

CWEs

CWE-441 CWE-918

Verify integrity in audit chain (admin only). AS-IS.