What is CVE-2026-67315?
axios versions 0.31.0-0.33.0 and 1.15.0-1.18.0 have a flaw in `shouldBypassProxy.js` where 0.0.0.0 is not treated as a loopback address, causing NO_PROXY bypass. This allows attackers to supply 0.0.0.0 URLs to route requests through proxies, potentially exposing local services. Update axios to the latest patched version.
Azərbaycanca: axios-in 0.31.0-0.33.0 və 1.15.0-1.18.0 versiyalarında 0.0.0.0 loopback ünvanını tanıma qüsuru `shouldBypassProxy.js`-də NO_PROXY qaydalarının yan keçilməsinə səbəb olur. Bu, təcavüzkarın 0.0.0.0 URL-ləri vasitəsilə sorğuları proxy üzərindən yönləndirərək lokal xidmətlərə çıxış imkanı yaradır. axios-i ən son yamaq olunmuş versiyaya yeniləmək tövsiyə olunur.
FAQ1
Which version ranges of axios are vulnerable to the NO_PROXY bypass in CVE-2026-67315?
axios versions 0.31.0 through 0.33.0 and 1.15.0 through 1.18.0 are affected because `shouldBypassProxy.js` does not treat 0.0.0.0 as a loopback address.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.