Axios HTTP Client NO_PROXY Bypass via 127.0.0.0/8 (before 1.15.1/0.31.1)
CVE-2026-42043 Published on April 24, 2026
Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This vulnerability is due to an incomplete for CVE-2025-62718, This vulnerability is fixed in 1.15.1 and 0.31.1.
Vulnerability Analysis
CVE-2026-42043 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. An automatable proof of concept (POC) exploit exists. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Types
What is an Allowlist / Allow List Vulnerability?
The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.
CVE-2026-42043 has been classified to as an Allowlist / Allow List vulnerability or weakness.
What is a Confused Deputy Vulnerability?
The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.
CVE-2026-42043 has been classified to as a Confused Deputy vulnerability or weakness.
What is a SSRF Vulnerability?
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. By providing URLs to unexpected hosts or ports, attackers can make it appear that the server is sending the request, possibly bypassing access controls such as firewalls that prevent the attackers from accessing the URLs directly. The server can be used as a proxy to conduct port scanning of hosts in internal networks, use other URLs such as that can access documents on the system (using file://), or use other protocols such as gopher:// or tftp://, which may provide greater control over the contents of requests.
CVE-2026-42043 has been classified to as a SSRF vulnerability or weakness.
Products Associated with CVE-2026-42043
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-42043 are published in these products:
Affected Versions
axios:- Version >= 1.0.0, < 1.15.1 is affected.
- Version < 0.31.1 is affected.
- Version 1780917531 and below * is unaffected.
- Version 1780910888 and below * is unaffected.
- Version 1778511348 and below * is unaffected.
- Version 1778383863 and below * is unaffected.
- Version 1778532610 and below * is unaffected.
- Version 1778508956 and below * is unaffected.
- Version 1778510461 and below * is unaffected.
- Version 1783451729 and below * is unaffected.
- Version 1780876734 and below * is unaffected.
- Version 1780600823 and below * is unaffected.
- Version 1779371594 and below * is unaffected.
- Version 1779293013 and below * is unaffected.
- Version 1779841586 and below * is unaffected.
- Version 1781187342 and below * is unaffected.
- Version 1782761244 and below * is unaffected.
- Version 1778156756 and below * is unaffected.
- Version 1780590717 and below * is unaffected.
- Version 1780467029 and below * is unaffected.
- Version 1780467147 and below * is unaffected.
- Version 1778645099 and below * is unaffected.
- Version 1778539338 and below * is unaffected.
- Version 1779814592 and below * is unaffected.
- Version 1779341289 and below * is unaffected.
- Version 1778191473 and below * is unaffected.
- Version 1778191378 and below * is unaffected.
- Version 1778163785 and below * is unaffected.
- Version 1778164208 and below * is unaffected.
- Version 1778163935 and below * is unaffected.
- Version 1778164042 and below * is unaffected.
- Version 1778163792 and below * is unaffected.
- Version 1778163909 and below * is unaffected.
- Version 1778163785 and below * is unaffected.
- Version 1778163986 and below * is unaffected.
- Version 1779822261 and below * is unaffected.
- Version 1779811412 and below * is unaffected.
- Version 1779689392 and below * is unaffected.
- Version 1780891395 and below * is unaffected.
- Version 1779204086 and below * is unaffected.
- Version 1779922205 and below * is unaffected.
- Version 1779811473 and below * is unaffected.
- Version 1781181673 and below * is unaffected.
- Version 1781032495 and below * is unaffected.
- Version 1780105179 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.