CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-42043

CVE-2026-42043: Axios NO_PROXY Protection Bypass via RFC 1122 Loopback Subnet

Alon Barad
Alon Barad
Software Engineer

May 5, 2026·6 min read·226 visits

Executive Summary (TL;DR)

Axios fails to validate the full 127.0.0.0/8 loopback subnet, allowing attackers to supply non-standard local IPs (e.g., 127.0.0.2) to bypass NO_PROXY rules and maliciously route internal traffic through external proxies.

Axios versions prior to 1.15.1 and 0.31.1 contain a security control bypass vulnerability in the `NO_PROXY` implementation. The issue originates from an incomplete fix for a previous vulnerability (CVE-2025-62718). By targeting non-standard loopback IP addresses within the 127.0.0.0/8 subnet, an attacker can bypass internal traffic protections and force Axios to route requests through an external proxy. This results in Server-Side Request Forgery (SSRF) and Confused Deputy attacks.

Vulnerability Overview

Axios is a widely used promise-based HTTP client for browser and Node.js environments. Applications frequently configure Axios to use an external proxy via the HTTP_PROXY environment variable for outbound traffic. To prevent internal or local traffic from being sent to the external proxy, developers utilize the NO_PROXY environment variable.

The vulnerability exists in the parsing logic responsible for determining if a target hostname represents a local interface. This defect constitutes a Permissive List of Allowed Inputs (CWE-183). The shouldBypassProxy helper fails to properly identify the complete IP space reserved for loopback operations.

Because Axios does not correctly identify these addresses, it routes the traffic to the configured external proxy rather than accessing the resource directly. This behavior allows attackers to execute a Server-Side Request Forgery (SSRF) and manipulate the proxy server into acting as a Confused Deputy (CWE-441, CWE-918).

Root Cause Analysis

The fundamental flaw resides within the isLoopback helper function located in lib/helpers/shouldBypassProxy.js. This logic is invoked when a requested URL does not literally match any of the hostnames specified in the NO_PROXY list. In such cases, the library falls back to verifying if both the target hostname and the NO_PROXY entry are loopback addresses.

In the vulnerable versions, the application implemented this check using a hardcoded JavaScript Set containing only three string literals: localhost, 127.0.0.1, and ::1. The validation logic relied entirely on strict equality (Set.has()) against the requested hostname. This approach violates RFC 1122 §3.2.1.3, which designates the entire 127.0.0.0/8 block for loopback routing.

When an attacker supplies a target URL using an alternative loopback address such as 127.0.0.2 or 127.10.10.10, the Set.has() check returns false. Axios concludes the target is a remote external host. Consequently, it applies the global proxy settings and forwards the request to the upstream HTTP_PROXY.

Code Analysis and Patch Review

The vulnerable implementation of the loopback verification utilized a highly restricted explicit allowlist. The code specifically checked for exact string matches, failing to account for IP subnets or routing equivalence.

// Vulnerable Implementation
const LOOPBACK_ADDRESSES = new Set(['localhost', '127.0.0.1', '::1']);
const isLoopback = (host) => LOOPBACK_ADDRESSES.has(host);

The patched versions (1.15.1 and 0.31.1) remove the reliance on the static literal set for IPv4 addresses. Instead, the developers implemented a parsing routine that splits the hostname and checks the leading octet. This correctly identifies any address originating in the 127 block.

// Patched Implementation (Conceptual Logic based on Commit)
const isLoopback = (host) => {
  if (host === 'localhost' || host === '::1') return true;
  const parts = host.split('.');
  if (parts.length === 4 && parts[0] === '127') {
    return parts.every(p => !isNaN(parseInt(p, 10)) && p >= 0 && p <= 255);
  }
  return false;
};

This update fundamentally resolves the logical gap left by the prior incomplete patch (CVE-2025-62718). By evaluating the mathematical constraints of the IPv4 structure rather than relying on string literals, the fix ensures comprehensive coverage of the RFC 1122 specification.

Exploitation Methodology

Exploiting this vulnerability requires specific environmental preconditions. The target application must utilize Axios for making outbound HTTP requests, have an active proxy configured (via HTTP_PROXY or Axios config), and rely on NO_PROXY to shield local services. Crucially, the application must process attacker-controlled input to dictate the destination URL of an Axios request.

The attacker crafts a payload utilizing a non-standard loopback address within the 127.0.0.0/8 subnet. For instance, the attacker provides http://127.0.0.2:6379/ as the URL input. Because Axios fails to recognize this as a loopback address, it ignores the NO_PROXY directive intended to keep local traffic internal.

The request is subsequently transmitted to the external proxy server. If the proxy server lacks its own localized protections, it processes the request and routes it based on its own network perspective. The proxy acts as a Confused Deputy, allowing the attacker to probe the proxy's internal network or access services bound to the proxy's localhost interface.

Impact Assessment

The vulnerability carries a CVSS 3.1 Base Score of 7.2 (High). The attack vector is strictly network-based and requires no elevated privileges or user interaction. The primary impact relates to confidentiality and integrity, as attackers can leverage the proxy infrastructure to interact with unauthorized services.

The scope is categorized as 'Changed' because the vulnerable application (Axios) is used to pivot an attack against a secondary infrastructure component (the proxy server). The extent of the compromise depends entirely on the network placement and configuration of the external proxy. If the proxy has access to sensitive backend APIs or administrative consoles, the damage can be substantial.

However, the vulnerability does not directly permit arbitrary code execution or denial of service against the Node.js application hosting Axios. The overall impact is bounded by the capabilities and reach of the targeted proxy server, limiting the exploitability in highly segmented zero-trust environments.

Remediation and Mitigation

The definitive remediation strategy is upgrading the Axios dependency to a patched version. Development teams must ensure their package manifest specifies Axios version 1.15.1, version 0.31.1, or later. Upgrading eliminates the vulnerability at the root cause by introducing correct subnet parsing logic.

If an immediate library upgrade is not feasible, administrators can implement configuration-based workarounds. The NO_PROXY environment variable should be updated to explicitly include the entire loopback CIDR block (127.0.0.0/8). In environments where CIDR notation is not supported by the underlying parsing logic, proxy support can be programmatically disabled for specific request flows by passing proxy: false within the Axios configuration object.

Application developers must also enforce rigorous input validation on all user-supplied URLs. Applications should reject explicit IP addresses in target URLs unless absolutely required. Implementing an architectural pattern that resolves hostnames prior to invoking the HTTP client provides an additional layer of defense against SSRF vectors.

Official Patches

AxiosGitHub Security Advisory
AxiosFix Commit

Fix Analysis (1)

Technical Appendix

CVSS Score
7.2/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
EPSS Probability
0.04%
Top 87% most exploited

Affected Systems

Axios (< 0.31.1)Axios (>= 1.0.0, < 1.15.1)Node.js Applications utilizing HTTP_PROXY with user-controlled Axios requests

Affected Versions Detail

Product
Affected Versions
Fixed Version
Axios
axios
< 0.31.10.31.1
Axios
axios
>= 1.0.0, < 1.15.11.15.1
AttributeDetail
CWE IDCWE-183, CWE-441, CWE-918
Attack VectorNetwork
CVSS v3.17.2
EPSS Score0.00044
ImpactSSRF / Confused Deputy
Exploit StatusProof of Concept
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1005Data from Local System
Collection
CWE-183
Permissive List of Allowed Inputs

The software uses a permissive list of allowed inputs to validate network addresses, failing to recognize alternative representations of loopback addresses.

Known Exploits & Detection

Technical AnalysisLogic flaw proof-of-concept allowing NO_PROXY bypass using 127.0.0.2

Vulnerability Timeline

Vulnerability Disclosed and Patched
2026-04-24

References & Sources

  • [1]Vendor Advisory (GHSA-pmwg-cvhr-8vh7)
  • [2]NVD Entry CVE-2026-42043
  • [3]CVE.org Record
  • [4]Axios Threat Model and Patch Commit
Related Vulnerabilities
CVE-2025-62718

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 4 hours ago•CVE-2026-92945
4.2

CVE-2026-92945: Sandbox Escape and Module Allowlist Bypass via Path Prefix Matching in vm2

A module allowlist bypass vulnerability (CVE-2026-92945 / GHSA-7q3f-wx44-378m) was identified in the vm2 sandboxing library prior to version 3.11.7. This flaw permits unauthenticated or untrusted code running within the sandbox environment to bypass explicit module restrictions. When the transitive resolution option is disabled, the system fails to validate file system path boundaries, allowing prefix-sharing sibling directories to be resolved and loaded, thereby escaping intended sandbox restrictions.

Amit Schendel
Amit Schendel
6 views•6 min read
•about 5 hours ago•CVE-2026-92941
10.0

CVE-2026-92941: Sandbox Escape and Process-Wide TLS Trust Store Manipulation in vm2

CVE-2026-92941 is a critical sandbox-escape and trust-manipulation vulnerability in the vm2 library (versions 3.11.3 to 3.11.6). This security flaw allows untrusted code executing within a NodeVM sandbox environment to compromise the global TLS trust store of the host Node.js process. By leveraging a design flaw where the host's native 'tls.setDefaultCACertificates' can be executed via a proxy wrapper, combined with a bridge unwrapping bypass in the 'url' module, an attacker can modify the process-wide default root Certificate Authorities. Consequently, all subsequent outbound TLS/HTTPS clients running on the host thread are forced to trust attacker-signed certificates, facilitating transparent Man-in-the-Middle (MitM) attacks. The vulnerability was resolved in version 3.11.7 of vm2 by introducing built-in member-level sanitization before applying read-only proxy wrappers.

Amit Schendel
Amit Schendel
4 views•10 min read
•about 6 hours ago•CVE-2026-92944
9.8

CVE-2026-92944: Sandbox Escape in vm2 via Stale V8 PromiseThenLookupChain Protector

A critical engine-level reachability failure in Node.js 26 running V8 14.6 allows attackers to escape the vm2 sandbox environment. When consecutive prototype properties are modified using sequential assignments, a V8 optimization bug fails to invalidate the PromiseThenLookupChain protector. By calling Promise.prototype.finally, the attacker bypasses the vm2 wrappers, hijacks the promise reaction using a custom constructor, triggers a calibrated stack overflow to capture a host-realm RangeError, and executes arbitrary shell commands on the host.

Alon Barad
Alon Barad
7 views•8 min read
•about 7 hours ago•CVE-2026-92939
9.9

CVE-2026-92939: Critical Sandbox Escape via Host Crypto setEngine Native Code Execution in vm2

A critical sandbox escape vulnerability in the vm2 library allows sandboxed JavaScript code to bypass containment and execute arbitrary native code on the host process. This occurs when the host's builtin crypto module is exposed to the NodeVM environment. Although vm2 implements a read-only proxy layer to restrict direct modifications to host properties, it does not prevent invocation of host-level functions. By calling the crypto.setEngine API with a path to a malicious native library on disk, an attacker can trigger OpenSSL's dynamic module loader. The host's operating system loader immediately runs the dynamic library's initializers/constructors before verifying engine compatibility, leading to remote code execution in the context of the host process.

Amit Schendel
Amit Schendel
6 views•5 min read
•about 8 hours ago•CVE-2026-92938
9.9

CVE-2026-92938: Remote Code Execution in vm2 via node:sqlite DatabaseSync Sandbox Escape

CVE-2026-92938 is a critical sandbox escape vulnerability in the vm2 library (versions 3.11.3 through 3.11.6) that allows arbitrary native code execution on the host when the node:sqlite built-in module is loaded inside a sandboxed NodeVM environment.

Amit Schendel
Amit Schendel
8 views•8 min read
•about 9 hours ago•CVE-2026-92937
10.0

CVE-2026-92937: Sandbox Escape leading to Remote Code Execution via Promise Indirection in vm2

CVE-2026-92937 is a critical sandbox escape vulnerability in the `vm2` Node.js library. Due to a logical failure in checking direct invocation targets inside the Proxy bridge, an attacker can register Promise callbacks using `Function.prototype.call` or `Function.prototype.apply` indirection. This bypasses the error sanitization wrappers, delivering raw host error objects directly to sandboxed callbacks and allowing the attacker to escape the sandbox and execute arbitrary shell commands on the host.

Amit Schendel
Amit Schendel
8 views•6 min read