CVE-2025-62718
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Axios is a promise-based HTTP client for JavaScript applications running in the browser and Node.js. It provides a simple API, flexible request and response interceptors, and built-in support for automatic JSON transformation, request cancellation, and timeouts to simplify communication with APIs and services.
A vulnerability (CVE-2025-62718) has been identified in Axios’s handling of NO_PROXY exclusions. Axios compares hostnames without correctly normalizing trailing dots or IPv6 brackets. Consequently, requests to localhost. or [::1] can pass through the configured proxy despite corresponding exclusions for localhost or ::1, potentially exposing sensitive traffic.
This behavior maps to CWE-918 (Server-Side Request Forgery) and CWE-441 (Unintended Proxy or Intermediary). An attacker who controls request URLs can exploit inconsistent hostname matching to route requests through a proxy that the application intended to bypass. The security impact depends on the configured proxy and its access to sensitive traffic or services.
Details
Module Info
- Product: Axios
- Affected packages:
axios - Affected versions: >=1.0.0, <1.15.0; <0.31.0
- GitHub repository: https://github.com/axios/axios
- Published packages: https://www.npmjs.com/package/axios
- Package manager: npm
- Fixed in:
- OSS Axios v1.15.1
- OSS Axios v0.31.1
- NES for Axios
Vulnerability Info
This medium-severity vulnerability affects Node.js applications using Axios with a configured proxy and NO_PROXY exclusions. The Axios advisory assigns a CVSS v3.1 score of 4.8.
An attacker can supply alternate hostname representations that fail exclusion matching. If the configured proxy is attacker-controlled, requests intended for direct delivery may expose sensitive information through that proxy.
The advisory associates this behavior with CWE-918 and CWE-441. Exploitation depends on attacker influence over request URLs and the application’s proxy configuration.
Mitigation
Users of affected Axios packages should apply one of the following mitigations:
- Upgrade to a patched version of the
axiospackage. - Leverage commercial support — HeroDevs provides security support for Axios.
