VDB
CVE-2026-67315
CVE-2026-67315
PUBLISHED
CVSS 6.9 MEDIUM
Reported by VulnCheck · Published August 1, 2026
axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.
Risk Scores
CVSS 4.0
6.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| axios | axios | 1.15.0, 1.18.0 |
| axios | axios | 0.31.0, 0.33.0 |
| chainguard | nextcloud-server-33 | 0, 0, 0 |
| chainguard | kibana-9.2 | 0, 0, 0 |
| chainguard | kibana-9.3 | 0, 0, 0 |
| chainguard | gitlab-rails-ce-fips-19.2 | 0, 0 |
| chainguard | kibana-9.4 | 0, 0, 0 |
| chainguard | opensearch-dashboards-2-fips | 0, 0, 0 |
| chainguard | wazuh-dashboard-fips | 0, 0 |
| chainguard | opensearch-dashboards-3-fips | 0, 0, 0 |
| chainguard | langfuse-fips-3 | 0, 0, 0 |
| chainguard | lerna | 0, 0, 0 |
| chainguard | langfuse-2 | 0, 0, 0 |
| chainguard | gitlab-rails-ce-19.2 | 0, 0 |
| wolfi | jitsucom-jitsu | 0, 0, 0 |
| chainguard | kibana-9.1 | 0, 0, 0 |
| chainguard | wazuh-dashboard | 0, 0 |
| chainguard | redisinsight | 0, 0 |
| wolfi | nextcloud-server-33 | 0, 0, 0 |
| chainguard | gitlab-rails-ce-fips-19.1 | 0, 0 |
…and 26 more
Timeline
- Jul 20, 2026 CVE Published
- Aug 1, 2026 Coalition ESS Score
- Aug 2, 2026 EPSS Score
- Aug 2, 2026 Security Advisory
- Aug 3, 2026 CVE Updated
- Aug 24, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Sep 2, 2026 EPSS Score
- Sep 2, 2026 Security Advisory
- Sep 6, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
References
- GitHub Security Advisory (GHSA-f4gw-2p7v-4548) vendor-advisory
- VulnCheck Advisory: axios 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0 third-party-advisory