CVE-2025-62718

Server-Side Request Forgery
Affects
Axios
in
Axios
No items found.
Versions
>=1.0.0, <1.15.0; <0.31.0

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Axios is a promise-based HTTP client for JavaScript applications running in the browser and Node.js. It provides a simple API, flexible request and response interceptors, and built-in support for automatic JSON transformation, request cancellation, and timeouts to simplify communication with APIs and services.

A vulnerability (CVE-2025-62718) has been identified in Axios’s handling of NO_PROXY exclusions. Axios compares hostnames without correctly normalizing trailing dots or IPv6 brackets. Consequently, requests to localhost. or [::1] can pass through the configured proxy despite corresponding exclusions for localhost or ::1, potentially exposing sensitive traffic.

This behavior maps to CWE-918 (Server-Side Request Forgery) and CWE-441 (Unintended Proxy or Intermediary). An attacker who controls request URLs can exploit inconsistent hostname matching to route requests through a proxy that the application intended to bypass. The security impact depends on the configured proxy and its access to sensitive traffic or services.

Details

Module Info

Vulnerability Info

This medium-severity vulnerability affects Node.js applications using Axios with a configured proxy and NO_PROXY exclusions. The Axios advisory assigns a CVSS v3.1 score of 4.8.

An attacker can supply alternate hostname representations that fail exclusion matching. If the configured proxy is attacker-controlled, requests intended for direct delivery may expose sensitive information through that proxy.

The advisory associates this behavior with CWE-918 and CWE-441. Exploitation depends on attacker influence over request URLs and the application’s proxy configuration.

Mitigation

Users of affected Axios packages should apply one of the following mitigations:

  • Upgrade to a patched version of the axios package.
  • Leverage commercial support — HeroDevs provides security support for Axios.
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Medium
ID
CVE-2025-62718
PROJECT Affected
Axios
Versions Affected
>=1.0.0, <1.15.0; <0.31.0
NES Versions Affected
Published date
September 29, 2026
≈ Fix date
September 1, 2026
Category
Server-Side Request Forgery
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Axios
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.