MEDIUM
Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges
Published Sep 30, 2026
6.9
MEDIUMCVSS 4.0
Description
Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges
Affected products
No data.
No data.
No data.
No Red Hat product state for this CVE.
axios
npm
Introduced 1.15.0 Fixed 1.20.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | axios | 1.15.0 | 1.20.0 |
Remediation
No remediation recorded yet.
Metrics
6.9 MEDIUM GHSA
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
Attack Vector Network
Attack Complexity Low
Attack Requirements Present
Privileges Required None
User Interaction None
Vulnerable System Confidentiality None
Vulnerable System Integrity None
Vulnerable System Availability None
Subsequent System Confidentiality High
Subsequent System Integrity None
Subsequent System Availability None
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
No EPSS score for this CVE.
Weaknesses (1)
References (5)
- https://github.com/advisories/GHSA-44g4-m2mj-wpvx Advisory
- https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a
- https://github.com/axios/axios/pull/11141
- https://github.com/axios/axios/releases/tag/v1.20.0
- https://github.com/axios/axios/security/advisories/GHSA-44g4-m2mj-wpvx
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status n/a
Assigner n/a
Published Sep 30, 2026
Updated n/a
Reserved n/a
Link CVE-2026-101899
CISA Vulnrichment
GHSA-44G4-M2MJ-WPVX Updated n/a