Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-67315

Опубликовано: 01 авг. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.

РелизСтатусПримечание
devel

not-affected

1.18.0-1
esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

needs-triage

upstream

released

1.18.0-1

Показывать по

EPSS

Процентиль: 21%
0.00291
Низкий

Связанные уязвимости

CVSS3: 5.8
redhat
около 1 месяца назад

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.

nvd
около 1 месяца назад

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.

debian
около 1 месяца назад

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to r ...

github
около 1 месяца назад

axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.

CVSS3: 5.8
fstec
около 2 месяцев назад

Уязвимость модуля shouldBypassProxy.js библиотеки axios, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 21%
0.00291
Низкий