AxiosApplication

CVE-2025-62718

CRITICAL · 9.9 CVSS v3.1 Published 2026-04-09
Fix available
A fix is available. Upgrade to 0.31.0 / 1.15.0 or later.
See remediation →
100/100
Remediation priority · Urgent
Public exploit Remotely reachable No privileges Zero-click Patch available

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the configured proxy. This goes against what developers expect and lets attackers force requests through a proxy, even if NO_PROXY is set up to protect loopback or internal services. This issue leads to the possibility of proxy bypass and SSRF vulnerabilities allowing attackers to reach sensitive loopback or internal services despite the configured protections. This vulnerability is fixed in 1.15.0 and 0.31.0.

In the news

Third-party coverage
Trending covered by 1 outlet this week · latest 3mo ago

Surfaced from public web coverage — external links open in a new tab.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · high confidence

Axios prior to 1.15.0 and 0.31.0 fails to properly normalize hostnames when evaluating NO_PROXY rules. Loopback addresses like 'localhost.' (with trailing dot) or IPv6 literals like [::1] bypass NO_PROXY matching, causing requests to be routed through configured proxies instead of sent directly. This allows attackers to force sensitive loopback/internal traffic through proxies, enabling SSRF and proxy bypass attacks.

MitigationUpgrade Axios to version 1.15.0 or 0.31.0 or later, which contains the corrected hostname normalization logic for NO_PROXY rule evaluation.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.

NVD · CPE data
AxiosApplication
Affected:< 0.31.0>= 1.0.0, < 1.15.0

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
Low

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Check installed Axios version
    Run 'npm list axios' or inspect package.json to see the axios version number
    Affected if The installed version is less than 0.31.0, or greater than or equal to 1.0.0 but less than 1.15.0
  2. Verify NO_PROXY configuration
    Check environment variables NO_PROXY, no_proxy, HTTPS_PROXY, HTTP_PROXY (or lowercase variants) for any configured proxy exclusion rules
    Affected if NO_PROXY or no_proxy is set but the hostname normalization bug exists in the Axios version
  3. Confirm proxy is configured
    Inspect environment for HTTP_PROXY, HTTPS_PROXY, http_proxy, or https_proxy environment variables
    Affected if A proxy is configured and NO_PROXY rules exist, but Axios fails to match them due to improper hostname normalization
  4. Check for vulnerable hostname usage
    Search codebase or runtime logs for requests to 'localhost.' (with trailing dot) or '[::1]' IPv6 literal addresses that should be excluded by NO_PROXY
    Affected if Requests are made to localhost variants or IPv6 loopback that should bypass the proxy but may be routed through it due to the normalization flaw

You are affected if you use a vulnerable Axios version (less than 0.31.0 or 1.0.0 to less than 1.15.0) with both a configured proxy and NO_PROXY rules, especially when making requests to localhost variants or IPv6 loopback addresses.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Upgrade available Upgrade to 0.31.0 / 1.15.0 or later
Fixed in 0.31.01.15.0
Vendor patch github.com →
Interim mitigation

Upgrade Axios to version 1.15.0 or 0.31.0 or later, which contains the corrected hostname normalization logic for NO_PROXY rule evaluation.

Recommended fix High confidence

Axios 1.15.0+ for 1.x branch, or 0.31.0+ for 0.x branch

  1. Identify your current Axios version by checking package.json or running `npm list axios`
  2. For Axios 1.x users: Run `npm install axios@^1.15.0` to upgrade to the fixed version
  3. For Axios 0.x users: Run `npm install axios@^0.31.0` to upgrade to the fixed version
  4. Alternatively, update the version in your package.json to `^1.15.0` (for 1.x) or `^0.31.0` (for 0.x) and run `npm install`
  5. Verify the upgrade was successful by running `npm list axios` and confirming the version number
  6. Test your application to ensure proxy behavior with NO_PROXY works correctly, particularly for localhost and IPv6 loopback addresses
Caveat Minimal risk - this is a security bug fix addressing proxy bypass; verify NO_PROXY handling for loopback addresses after upgrade

Generated from the published advisory — verify against the referenced sources before acting.

Fix this in Axios Scoped from the published advisory
  • Consultation1.0 h
  • Implementation1.0 h
  • Testing2.0 h
  • Review / QA0.5 h
4.5 hours of engineering $770
Get the upgrade done

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $1,232.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2025-62718 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2025-62718 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data