Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6hqm-hm2v-3p2p

Опубликовано: 01 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.

axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.

EPSS

Процентиль: 21%
0.00291
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-183

Связанные уязвимости

nvd
2 дня назад

axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.

debian
2 дня назад

axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loo ...

EPSS

Процентиль: 21%
0.00291
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-183