Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-44492

Опубликовано: 11 июн. 2026
Источник: nvd
CVSS3: 8.6
EPSS Низкий

Описание

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe) still routes through the configured proxy. Node.js resolves these addresses to the underlying IPv4 host, so the request reaches the internal service via the proxy rather than being blocked. This vulnerability is fixed in 0.32.0 and 1.16.0.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*
Версия до 0.32.0 (исключая)
cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*
Версия от 1.0.0 (включая) до 1.16.0 (исключая)

EPSS

Процентиль: 55%
0.0087
Низкий

8.6 High

CVSS3

Дефекты

CWE-918
CWE-289

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 2 месяцев назад

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe) still routes through the configured proxy. Node.js resolves these addresses to the underlying IPv4 host, so the request reaches the internal service via the proxy rather than being blocked. This vulnerability is fixed in 0.32.0 and 1.16.0.

CVSS3: 8.6
redhat
около 2 месяцев назад

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe) still routes through the configured proxy. Node.js resolves these addresses to the underlying IPv4 host, so the request reaches the internal service via the proxy rather than being blocked. This vulnerability is fixed in 0.32.0 and 1.16.0.

CVSS3: 8.6
debian
около 2 месяцев назад

Axios is a promise based HTTP client for the browser and Node.js. Prio ...

CVSS3: 8.6
github
2 месяца назад

axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)

CVSS3: 8.6
fstec
2 месяца назад

Уязвимость файла lib/helpers/shouldBypassProxy.js библиотеки axios, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 55%
0.0087
Низкий

8.6 High

CVSS3

Дефекты

CWE-918
CWE-289