AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-101899.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 6.9CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 30, 2026

Disclosure summary

## Summary Axios supports proxy environment variables and evaluates `NO_PROXY` exclusions in the Node.js adapter. CIDR-form `NO_PROXY` entries such as `127.0.0.0/8`, `10.0.0.0/8`, or `169.254.169.254/32` are not interpreted as IP ranges. As a result, a request to an IP address inside a configured CIDR exclusion can still be sent through the configured proxy. This affects deployments that rely on CIDR notation to keep loopback, private, Kubernetes, CI, or cloud metadata traffic away from proxy infrastructure. ## Impact If the configured proxy is outside the intended trust boundary, requests that operators expected to bypass the proxy may be exposed to it. For plaintext HTTP targets, the proxy can see and modify URLs, headers, and bodies. For HTTPS targets, the proxy still observes connection metadata and may receive CONNECT requests that policy expected to avoid. This is a proxy exclusion bypass, not arbitrary proxy injection by itself. ## Affected Functionality Affected: - Node.js adapter proxy environment handling. - `HTTP_PROXY`, `HTTPS_PROXY`, `NO_PROXY`, or lowercase equivalents. - CIDR entries in `NO_PROXY`. Not affected: - Exact host or exact IP `NO_PROXY` entries where axios

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-44g4-m2mj-wpvx

Open original source · Updated Sep 30, 2026

Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges

Source severity: MEDIUM / 6.9

EcosystemPackageAffected rangeFirst patched
npmaxios>= 1.15.0, < 1.20.01.20.0

Original records & references

PUBLISHED 2026-09-30T11:32:30-04:00
MODIFIED 2026-09-30T11:32:34-04:00
INGESTED 2026-10-06T11:43:09-04:00