{"id":"CVE-2026-67315","aliases":["GHSA-f4gw-2p7v-4548"],"url":"https://o3.security/vulnerability/CVE-2026-67315","summary":"axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0","details":"axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially exposing local services when the proxy can reach the destination.","published":"2026-08-01T12:22:18.103Z","modified":"2026-09-02T16:10:54.099790618Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"axios","fixedVersion":"1.18.0"},{"ecosystem":"npm","name":"axios","fixedVersion":"0.33.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67315.json"},{"type":"ADVISORY","url":"https://github.com/axios/axios/security/advisories/GHSA-f4gw-2p7v-4548"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67315"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/axios-before-no-proxy-bypass-via"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-02T16:10:54.099790618Z"}}