Listen to this Post
Axios 1.17.0 honors HTTP_PROXY / HTTPS_PROXY.
Axios supports NO_PROXY host exclusions.
CIDR-form NO_PROXY entries are not treated as network ranges.
Example: NO_PROXY=127.0.0.0/8.
HTTP_PROXY=http://127.0.0.1:
Target URL=http://127.0.0.1:
127.0.0.1 is inside 127.0.0.0/8.
Operator expects Axios to bypass proxy.
Axios instead sends request through HTTP_PROXY.
This is a proxy exclusion bypass.
It is not arbitrary proxy injection by itself.
Exact host exclusions work.
CIDR exclusions silently fail.
Relevant logic is in Node proxy handling.
NO_PROXY / no_proxy evaluation is affected.
shouldBypassProxy parses host and optional port.
It normalizes hostnames.
It compares exact hostnames.
It compares suffix entries.
It compares wildcard-prefix entries.
It compares loopback equivalents.
It does not parse CIDR notation.
Local verification on axios 1.18.1 expected true.
Affected deployments rely on CIDR notation.
They exclude loopback, private, Kubernetes, CI, cloud metadata.
Common CIDR entries include 127.0.0.0/8.
Common CIDR entries include 10.0.0.0/8.
Common CIDR entries include 172.16.0.0/12.
Common CIDR entries include 192.168.0.0/16.
Common CIDR entries include 169.254.169.254/32.
If proxy is outside trust boundary, requests may be exposed.
Plaintext HTTP proxy can see and modify URLs, headers, bodies.
HTTPS proxy observes connection metadata.
HTTPS proxy may receive CONNECT requests policy expected to avoid.
Impact is configuration-dependent.
CI/CD runners, containers, Kubernetes, enterprise, cloud are impacted.
Workaround: use exact host or IP entries.
Workaround: set proxy: false per request.
DailyCVE Form:
Platform: Axios Node.js
Version: 1.17.0
Vulnerability : NO_PROXY CIDR bypass
Severity: Unspecified
date: Not provided
Prediction: Unknown patch date
What Undercode Say:
Analytics
export HTTP_PROXY=http://127.0.0.1:34315 export HTTPS_PROXY=http://127.0.0.1:34315 export NO_PROXY=127.0.0.0/8 export no_proxy=127.0.0.0/8 node poc-no-proxy-cidr-axios.mjs
import http from 'http';
import axios from 'axios';
process.env.http_proxy = 'http://127.0.0.1:34315';
process.env.HTTP_PROXY = 'http://127.0.0.1:34315';
process.env.no_proxy = '127.0.0.0/8';
process.env.NO_PROXY = '127.0.0.0/8';
await axios.get('http://127.0.0.1:43993/metadata', { timeout: 2000 });
Exploit: (Educational Purposes!)
POC_INTERNAL_HOST=127.0.0.1 node poc-no-proxy-cidr-axios.mjs
NO_PROXY=127.0.0.0/8 HTTP_PROXY=http://127.0.0.1:34315 Target URL=http://127.0.0.1:43993/metadata Response=proxy saw request for http://127.0.0.1:43993/metadata Proxy hits=1 Internal direct hits=0 POC RESULT: axios sent the target through the proxy with NO_PROXY=127.0.0.0/8.
POC_INTERNAL_HOST=127.0.0.1 POC_NO_PROXY=127.0.0.1 node poc-no-proxy-cidr-axios.mjs
NO_PROXY=127.0.0.1 Response=internal service saw /metadata Proxy hits=0 Internal direct hits=1 POC RESULT: axios bypassed the proxy with NO_PROXY=127.0.0.1.
Protection: from this CVE
export NO_PROXY=127.0.0.1,localhost,169.254.169.254
await axios.get(targetUrl, { proxy: false });
Use exact host/IP entries.
Patch when CIDR matching fixed.
Validate proxy trust boundary.
Impact:
Proxy exclusion bypass.
Requests to loopback, private, Kubernetes, CI, cloud metadata may traverse proxy.
Plaintext HTTP proxy can see and modify URLs, headers, bodies.
HTTPS proxy observes connection metadata and may receive CONNECT requests.
May expose request URLs, internal hostnames, paths, headers, credentials.
Not arbitrary proxy injection by itself.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

