Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67315

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 5.8
EPSS Низкий

Описание

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.

A flaw was found in axios. This vulnerability occurs because the software fails to correctly identify 0.0.0.0 as a local loopback address when evaluating NO_PROXY rules. A remote attacker could exploit this by providing a 0.0.0.0 URL, causing requests to bypass intended proxy restrictions. This could lead to the exposure of internal services to the configured proxy, potentially allowing unauthorized access to local resources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 8mta/mta-ui-rhel9Fix deferred
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Fix deferred
Network Observability Operatornetwork-observability/network-observability-console-plugin-pf4-rhel9Fix deferred
Network Observability Operatornetwork-observability/network-observability-console-plugin-pf5-rhel9Fix deferred
Network Observability Operatornetwork-observability/network-observability-console-plugin-rhel9Fix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-ui-rhel9Fix deferred
OpenShift Service Mesh 3openshift-service-mesh/kiali-ossmc-rhel9Fix deferred
OpenShift Service Mesh 3openshift-service-mesh/kiali-rhel9Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-115
https://bugzilla.redhat.com/show_bug.cgi?id=2510019axios: axios: NO_PROXY bypass allows exposure of local services

EPSS

Процентиль: 21%
0.00291
Низкий

5.8 Medium

CVSS3

Связанные уязвимости

ubuntu
около 1 месяца назад

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.

nvd
около 1 месяца назад

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.

debian
около 1 месяца назад

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to r ...

github
около 1 месяца назад

axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.

CVSS3: 5.8
fstec
около 2 месяцев назад

Уязвимость модуля shouldBypassProxy.js библиотеки axios, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 21%
0.00291
Низкий

5.8 Medium

CVSS3