CVE-2025-62718
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the configured proxy. This goes against what developers expect and lets attackers force requests through a proxy, even if NO_PROXY is set up to protect loopback or internal services. This issue leads to the possibility of proxy bypass and SSRF vulnerabilities allowing attackers to reach sensitive loopback or internal services despite the configured protections. This vulnerability is fixed in 1.15.0 and 0.31.0.
In the news
Third-party coverageSurfaced from public web coverage — external links open in a new tab.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidenceAxios prior to 1.15.0 and 0.31.0 fails to properly normalize hostnames when evaluating NO_PROXY rules. Loopback addresses like 'localhost.' (with trailing dot) or IPv6 literals like [::1] bypass NO_PROXY matching, causing requests to be routed through configured proxies instead of sent directly. This allows attackers to force sensitive loopback/internal traffic through proxies, enabling SSRF and proxy bypass attacks.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.
NVD · CPE data< 0.31.0>= 1.0.0, < 1.15.0CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- None
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- Low
- Availability
- Low
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Check installed Axios versionRun 'npm list axios' or inspect package.json to see the axios version numberAffected if The installed version is less than 0.31.0, or greater than or equal to 1.0.0 but less than 1.15.0
-
Verify NO_PROXY configurationCheck environment variables NO_PROXY, no_proxy, HTTPS_PROXY, HTTP_PROXY (or lowercase variants) for any configured proxy exclusion rulesAffected if NO_PROXY or no_proxy is set but the hostname normalization bug exists in the Axios version
-
Confirm proxy is configuredInspect environment for HTTP_PROXY, HTTPS_PROXY, http_proxy, or https_proxy environment variablesAffected if A proxy is configured and NO_PROXY rules exist, but Axios fails to match them due to improper hostname normalization
-
Check for vulnerable hostname usageSearch codebase or runtime logs for requests to 'localhost.' (with trailing dot) or '[::1]' IPv6 literal addresses that should be excluded by NO_PROXYAffected if Requests are made to localhost variants or IPv6 loopback that should bypass the proxy but may be routed through it due to the normalization flaw
You are affected if you use a vulnerable Axios version (less than 0.31.0 or 1.0.0 to less than 1.15.0) with both a configured proxy and NO_PROXY rules, especially when making requests to localhost variants or IPv6 loopback addresses.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scoped0.31.01.15.0
Upgrade Axios to version 1.15.0 or 0.31.0 or later, which contains the corrected hostname normalization logic for NO_PROXY rule evaluation.
Axios 1.15.0+ for 1.x branch, or 0.31.0+ for 0.x branch
- Identify your current Axios version by checking package.json or running `npm list axios`
- For Axios 1.x users: Run `npm install axios@^1.15.0` to upgrade to the fixed version
- For Axios 0.x users: Run `npm install axios@^0.31.0` to upgrade to the fixed version
- Alternatively, update the version in your package.json to `^1.15.0` (for 1.x) or `^0.31.0` (for 0.x) and run `npm install`
- Verify the upgrade was successful by running `npm list axios` and confirming the version number
- Test your application to ensure proxy behavior with NO_PROXY works correctly, particularly for localhost and IPv6 loopback addresses
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation1.0 h
- Implementation1.0 h
- Testing2.0 h
- Review / QA0.5 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $1,232.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2025-62718 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sources- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
- datatracker.ietf.org
- datatracker.ietf.org
- github.com
- github.com
- github.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- bugzilla.redhat.com
- security.access.redhat.com
- nvd.nist.gov
Practitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2025-62718 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data