REDHAT-BUG-2461626: High severity npm/axios vulnerability
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NOPROXY protection. This vulnerability is due to an incomplete for CVE-2025-62718, This vulnerability is fixed in 1.15.1 and 0.31.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Axiosto a version that resolves this vulnerability.Fixed in 1.15.1 - Upgrade
Upgrade
Axiosto a version that resolves this vulnerability.Fixed in 0.31.1
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2461626?
The severity of REDHAT-BUG-2461626 is high, rated at 7.
How do I fix REDHAT-BUG-2461626?
To fix REDHAT-BUG-2461626, update Axios to version 1.15.1 or 0.31.1 or later.
What software is affected by REDHAT-BUG-2461626?
The software affected by REDHAT-BUG-2461626 is npm/axios.
What are the consequences of REDHAT-BUG-2461626?
An attacker exploiting REDHAT-BUG-2461626 can bypass NO_PROXY protections by influencing the target URL.
When was REDHAT-BUG-2461626 published?
REDHAT-BUG-2461626 was published on April 24, 2026.