Disclosure summary
## Summary Axios `shouldBypassProxy()` normalizes hostnames with `hostname.replace(/\.+$/, '')`. For a hostname shaped as many dots followed by a non-dot, the anchored regex can perform quadratic backtracking. Because axios re-evaluates proxy bypass rules for redirected requests, a malicious server can trigger this synchronous work through a crafted redirect `Location`. The issue affects Node.js applications that use environment proxy variables with `NO_PROXY` and allow redirects. ## Impact An attacker-controlled server can return a redirect whose hostname causes the axios process to spend significant CPU time in synchronous hostname normalization. During this time, the Node.js event loop is blocked and the application cannot handle other work on that thread. This is an availability-only issue. It does not disclose request data or modify requests. ## Affected Functionality Affected: - Node.js HTTP adapter. - Environment proxy handling through `HTTP_PROXY` or `HTTPS_PROXY`. - `NO_PROXY` or `no_proxy` set to a non-empty value. - Redirects followed by axios or `follow-redirects`. Not affected: - Browser adapters. - Requests with `proxy: false`. - Requests with no `NO_PROXY` value. - R
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-mghh-pgcx-3jjj
Open original source · Updated Sep 30, 2026
Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location
Source severity: HIGH / 8.2
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | axios | >= 1.15.0, < 1.20.0 | 1.20.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-30T11:03:02-04:00
MODIFIED 2026-09-30T11:03:03-04:00
INGESTED 2026-10-06T11:43:09-04:00