VDB

CVE-2026-67315

CVE-2026-67315 PUBLISHED CVSS 6.9 MEDIUM

Reported by VulnCheck · Published August 1, 2026

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.

Risk Scores

CVSS 4.0
6.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N

Affected Products

VendorProductVersions
axiosaxios1.15.0, 1.18.0
axiosaxios0.31.0, 0.33.0
chainguardnextcloud-server-330, 0, 0
chainguardkibana-9.20, 0, 0
chainguardkibana-9.30, 0, 0
chainguardgitlab-rails-ce-fips-19.20, 0
chainguardkibana-9.40, 0, 0
chainguardopensearch-dashboards-2-fips0, 0, 0
chainguardwazuh-dashboard-fips0, 0
chainguardopensearch-dashboards-3-fips0, 0, 0
chainguardlangfuse-fips-30, 0, 0
chainguardlerna0, 0, 0
chainguardlangfuse-20, 0, 0
chainguardgitlab-rails-ce-19.20, 0
wolfijitsucom-jitsu0, 0, 0
chainguardkibana-9.10, 0, 0
chainguardwazuh-dashboard0, 0
chainguardredisinsight0, 0
wolfinextcloud-server-330, 0, 0
chainguardgitlab-rails-ce-fips-19.10, 0

…and 26 more

Timeline

  • Jul 20, 2026 CVE Published
  • Aug 1, 2026 Coalition ESS Score
  • Aug 2, 2026 EPSS Score
  • Aug 2, 2026 Security Advisory
  • Aug 3, 2026 CVE Updated
  • Aug 24, 2026 EPSS Score
  • Aug 28, 2026 EPSS Score
  • Sep 2, 2026 EPSS Score
  • Sep 2, 2026 Security Advisory
  • Sep 6, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›