CVE-2026-101899: Npm/axios vulnerability

Published Sep 30, 2026
·
Updated

Summary

Axios supports proxy environment variables and evaluates NOPROXY exclusions in the Node.js adapter. CIDR-form NOPROXY entries such as 127.0.0.0/8, 10.0.0.0/8, or 169.254.169.254/32 are not interpreted as IP ranges. As a result, a request to an IP address inside a configured CIDR exclusion can still be sent through the configured proxy.

This affects deployments that rely on CIDR notation to keep loopback, private, Kubernetes, CI, or cloud metadata traffic away from proxy infrastructure.

Impact

If the configured proxy is outside the intended trust boundary, requests that operators expected to bypass the proxy may be exposed to it. For plaintext HTTP targets, the proxy can see and modify URLs, headers, and bodies. For HTTPS targets, the proxy still observes connection metadata and may receive CONNECT requests that policy expected to avoid.

This is a proxy exclusion bypass, not arbitrary proxy injection by itself.

Affected Functionality

Affected:

- Node.js adapter proxy environment handling. - HTTPPROXY, HTTPSPROXY, NOPROXY, or lowercase equivalents. - CIDR entries in NOPROXY.

Not affected:

- Exact host or exact IP NOPROXY entries where axios matching succeeds. - Requests configured with proxy: false. - Browser adapters.

Technical Details

lib/helpers/shouldBypassProxy.js parses each NOPROXY entry into a host and optional port, normalizes hostnames, and then compares exact hostnames, suffix entries, wildcard-prefix entries, and loopback equivalents. It does not parse CIDR notation.

Local verification on axios 1.18.1:

js process.env.NOPROXY = '127.0.0.0/8'; shouldBypassProxy('http://127.0.0.1:1234/'); // false

The expected result for CIDR-aware bypass policy is true.

Proof of Concept of Attack

Constrained local demonstration:

1. Set HTTPPROXY=http://127.0.0.1:<proxy-port>. 2. Set NOPROXY=127.0.0.0/8. 3. Request http://127.0.0.1:<internal-port>/metadata. 4. Observe that axios sends the request through the proxy instead of directly to the internal listener.

Workarounds

Use exact host or IP entries in NOPROXY for sensitive destinations until CIDR matching is fixed, for example 127.0.0.1,localhost,169.254.169.254. For individual requests that must not use a proxy, set proxy: false.

<details> <summary><h3>Original report</h3></summary> Summary

Axios 1.17.0 honors HTTPPROXY / HTTPSPROXY and supports NOPROXY host exclusions, but CIDR-form NOPROXY entries such as 127.0.0.0/8 are not treated as network ranges. As a result, requests to IPs covered by a configured CIDR exclusion may still be sent through the configured proxy.

In the attached PoC, a request to 127.0.0.1 is sent through HTTPPROXY despite NOPROXY=127.0.0.0/8.

This can cause proxy exclusion bypass in environments where operators use CIDR notation to exclude loopback, private, internal, Kubernetes, CI, or cloud metadata address ranges from proxying.

Details

Axios supports proxy environment variables, including HTTPPROXY / HTTPSPROXY and NOPROXY-style exclusions. Axios’s threat model treats environment proxy handling as security-relevant and lists NOPROXY as a mitigation for proxy environment variable hijack, including hardening for CIDR ranges, IPv6 literals, and wildcard patterns. See: https://github.com/axios/axios/blob/a8e4f13aeecc45a3b8fab3ecfd9ddb5d70fb772b/THREATMODEL.md#t-r9-proxy-environment-variable-hijack

The issue is that CIDR-form NOPROXY entries are not interpreted as network ranges. For example:

text NOPROXY=127.0.0.0/8 HTTPPROXY=http://127.0.0.1:<proxy-port> Target URL=http://127.0.0.1:<internal-port>/metadata

Since 127.0.0.1 is inside 127.0.0.0/8, an operator may reasonably expect Axios to bypass the proxy for this request. Instead, Axios sends the request through HTTPPROXY.

This appears to affect the proxy bypass decision path used for NOPROXY / noproxy handling. The relevant behavior is in Axios's Node proxy handling and NOPROXY evaluation logic, including the shouldBypassProxy helper introduced for noproxy hostname normalization and bypass checks.

The issue is not that Axios ignores NOPROXY entirely. Exact host exclusions work. The issue is specifically that CIDR-form exclusions are silently treated as non-matching host/domain tokens rather than as network ranges, causing the request to be proxied.

This is security-relevant because CIDR notation is commonly used in container, CI, enterprise proxy, and cloud environments for ranges such as:

text 127.0.0.0/8 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 169.254.169.254/32

If operators rely on those entries to prevent internal or metadata-style requests from traversing a proxy, Axios may violate that expectation.

PoC

js import http from 'http'; import axios from 'axios';

function listen(server, host) { return new Promise((resolve, reject) => { server.once('error', reject); server.listen(0, host, () => resolve(server.address().port)); }); }

function close(server) { return new Promise((resolve) => server.close(resolve)); }

let proxyHits = 0; let internalHits = 0;

const internal = http.createServer((req, res) => { internalHits += 1; res.writeHead(200, { 'content-type': 'text/plain' }); res.end(internal service saw ${req.url}); });

const proxy = http.createServer((req, res) => { proxyHits += 1; res.writeHead(200, { 'content-type': 'text/plain' }); res.end(proxy saw request for ${req.url}); });

const internalHost = process.env.POCINTERNALHOST || '127.0.0.2'; const proxyHost = process.env.POCPROXYHOST || '127.0.0.1';

let internalPort; let proxyPort;

try { internalPort = await listen(internal, internalHost); proxyPort = await listen(proxy, proxyHost); } catch (error) { console.error('Failed to bind local PoC servers.'); console.error('On some systems 127.0.0.2 is unavailable; try:'); console.error(' POCINTERNALHOST=127.0.0.1 node poc-no-proxy-cidr-axios.mjs'); console.error(''); throw error; }

const targetUrl = http://${internalHost}:${internalPort}/metadata; const proxyUrl = http://${proxyHost}:${proxyPort}; const noProxy = process.env.POCNOPROXY || '127.0.0.0/8';

process.env.httpproxy = proxyUrl; process.env.HTTPPROXY = proxyUrl; process.env.noproxy = noProxy; process.env.NOPROXY = noProxy;

console.log('Axios NOPROXY CIDR full axios network PoC'); console.log(axios VERSION=${axios.VERSION || 'unknown'}); console.log(NOPROXY=${process.env.noproxy}); console.log(HTTPPROXY=${process.env.httpproxy}); console.log(Target URL=${targetUrl}); console.log('');

try { const response = await axios.get(targetUrl, { timeout: 2000, });

console.log(Response=${response.data}); console.log(Proxy hits=${proxyHits}); console.log(Internal direct hits=${internalHits}); console.log('');

if (proxyHits > 0 && internalHits === 0) { console.log(POC RESULT: axios sent the target through the proxy with NOPROXY=${noProxy}.); } else if (proxyHits === 0 && internalHits > 0) { console.log(POC RESULT: axios bypassed the proxy with NOPROXY=${noProxy}.); } else { console.log('POC RESULT: mixed/ambiguous routing; inspect counts above.'); } } finally { delete process.env.httpproxy; delete process.env.HTTPPROXY; delete process.env.noproxy; delete process.env.NOPROXY; await close(proxy); await close(internal); }

Run the failing CIDR case:

bash POCINTERNALHOST=127.0.0.1 node poc-no-proxy-cidr-axios.mjs

Observed:

text Axios NOPROXY CIDR full axios network PoC axios VERSION=1.17.0 NOPROXY=127.0.0.0/8 HTTPPROXY=http://127.0.0.1:34315 Target URL=http://127.0.0.1:43993/metadata

Response=proxy saw request for http://127.0.0.1:43993/metadata Proxy hits=1 Internal direct hits=0

POC RESULT: axios sent the target through the proxy with NOPROXY=127.0.0.0/8.

Control

Axios does honor exact IP NOPROXY entries:

bash POCINTERNALHOST=127.0.0.1 POCNOPROXY=127.0.0.1 node poc-no-proxy-cidr-axios.mjs

Expected:

text NOPROXY=127.0.0.1 Response=internal service saw /metadata Proxy hits=0 Internal direct hits=1

POC RESULT: axios bypassed the proxy with NOPROXY=127.0.0.1.

This shows the issue is not that NOPROXY is ignored entirely. The bypass failure is specific to CIDR-form entries such as 127.0.0.0/8.

Impact

This is a proxy exclusion bypass caused by unsupported CIDR matching in NOPROXY.

The impact is configuration-dependent. It affects Axios users in Node.js environments who rely on proxy environment variables and configure NOPROXY using CIDR notation to exclude internal, loopback, private, Kubernetes, CI, or cloud metadata ranges.

Potentially impacted environments include:

- CI/CD runners with globally injected HTTPPROXY / HTTPSPROXY. - Containers inheriting proxy variables from the host or orchestrator. - Kubernetes workloads using NOPROXY for cluster-internal service ranges. - Enterprise networks using HTTP proxies with internal network exclusions. - Cloud workloads relying on NOPROXY to keep metadata or internal service requests off proxy infrastructure.

If a configured proxy is compromised, attacker-controlled, overly broad, or outside the intended trust boundary, requests that operators expected to stay direct may instead be exposed to that proxy. This may expose request URLs, internal hostnames, paths, headers, or credentials depending on application behavior.

This should not be characterized as arbitrary proxy injection by itself. The issue is that Axios silently fails to enforce common CIDR-form proxy exclusions, which can undermine proxy bypass policy and defense-in-depth assumptions. </details>

---

Affected Software

1 affected componentFixes available
npm/axios>=1.15.0<1.20.0
1.20.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/axios to a version that resolves this vulnerability.

    Fixed in 1.20.0
  2. Configuration

    Use exact host or IP entries in NO_PROXY for sensitive destinations instead of CIDR-form entries until CIDR matching is fixed.

    Axios Node.js adapter NO_PROXY = 127.0.0.1,localhost,169.254.169.254
  3. Configuration

    Set proxy: false for requests that must not use a proxy.

    Axios individual requests proxy = false

Event History

Sep 30, 2026
Advisory Published
via GitHub·03:32 PM
Data Sourced
via GitHub·03:32 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using Axios's Node.js adapter with proxy environment variables configured and CIDR-form entries in NO_PROXY are exposed. This includes environments relying on CIDR exclusions for loopback, private, Kubernetes, CI, or cloud metadata addresses.

2

What must an attacker be able to do to take advantage of this?

A request must be made to an IP address that falls within a CIDR entry in NO_PROXY while Axios is configured to use an HTTP or HTTPS proxy. The configured proxy must also be outside the intended trust boundary for exposure to occur.

3

Are exact NO_PROXY exclusions affected?

No. Exact host and exact IP address entries in NO_PROXY are not affected; the issue is specific to CIDR-form entries.

4

What is exposed if traffic is sent through the proxy?

For plaintext HTTP, the proxy can view and modify URLs, headers, and bodies. For HTTPS, it can observe connection metadata and receive CONNECT requests that were expected to bypass the proxy.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203