Disclosure summary
## Summary Axios supports proxy environment variables and evaluates `NO_PROXY` exclusions in the Node.js adapter. CIDR-form `NO_PROXY` entries such as `127.0.0.0/8`, `10.0.0.0/8`, or `169.254.169.254/32` are not interpreted as IP ranges. As a result, a request to an IP address inside a configured CIDR exclusion can still be sent through the configured proxy. This affects deployments that rely on CIDR notation to keep loopback, private, Kubernetes, CI, or cloud metadata traffic away from proxy infrastructure. ## Impact If the configured proxy is outside the intended trust boundary, requests that operators expected to bypass the proxy may be exposed to it. For plaintext HTTP targets, the proxy can see and modify URLs, headers, and bodies. For HTTPS targets, the proxy still observes connection metadata and may receive CONNECT requests that policy expected to avoid. This is a proxy exclusion bypass, not arbitrary proxy injection by itself. ## Affected Functionality Affected: - Node.js adapter proxy environment handling. - `HTTP_PROXY`, `HTTPS_PROXY`, `NO_PROXY`, or lowercase equivalents. - CIDR entries in `NO_PROXY`. Not affected: - Exact host or exact IP `NO_PROXY` entries where axios
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-44g4-m2mj-wpvx
Open original source · Updated Sep 30, 2026
Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges
Source severity: MEDIUM / 6.9
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | axios | >= 1.15.0, < 1.20.0 | 1.20.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-30T11:32:30-04:00
MODIFIED 2026-09-30T11:32:34-04:00
INGESTED 2026-10-06T11:43:09-04:00