Axios, NO_PROXY CIDR Proxy Exclusion Bypass, CVE ID: N/A (Unspecified) -DC-Sep2026-2682

Listen to this Post

Axios 1.17.0 honors HTTP_PROXY / HTTPS_PROXY.

Axios supports NO_PROXY host exclusions.

CIDR-form NO_PROXY entries are not treated as network ranges.

Example: NO_PROXY=127.0.0.0/8.

HTTP_PROXY=http://127.0.0.1:.
Target URL=http://127.0.0.1:/metadata.

127.0.0.1 is inside 127.0.0.0/8.

Operator expects Axios to bypass proxy.

Axios instead sends request through HTTP_PROXY.

This is a proxy exclusion bypass.

It is not arbitrary proxy injection by itself.

Exact host exclusions work.

CIDR exclusions silently fail.

Relevant logic is in Node proxy handling.

NO_PROXY / no_proxy evaluation is affected.

shouldBypassProxy parses host and optional port.

It normalizes hostnames.

It compares exact hostnames.

It compares suffix entries.

It compares wildcard-prefix entries.

It compares loopback equivalents.

It does not parse CIDR notation.

Local verification on axios 1.18.1 expected true.

Affected deployments rely on CIDR notation.

They exclude loopback, private, Kubernetes, CI, cloud metadata.

Common CIDR entries include 127.0.0.0/8.

Common CIDR entries include 10.0.0.0/8.

Common CIDR entries include 172.16.0.0/12.

Common CIDR entries include 192.168.0.0/16.

Common CIDR entries include 169.254.169.254/32.

If proxy is outside trust boundary, requests may be exposed.
Plaintext HTTP proxy can see and modify URLs, headers, bodies.

HTTPS proxy observes connection metadata.

HTTPS proxy may receive CONNECT requests policy expected to avoid.

Impact is configuration-dependent.

CI/CD runners, containers, Kubernetes, enterprise, cloud are impacted.

Workaround: use exact host or IP entries.

Workaround: set proxy: false per request.

DailyCVE Form:

Platform: Axios Node.js
Version: 1.17.0
Vulnerability : NO_PROXY CIDR bypass
Severity: Unspecified
date: Not provided

Prediction: Unknown patch date

What Undercode Say:

Analytics

export HTTP_PROXY=http://127.0.0.1:34315
export HTTPS_PROXY=http://127.0.0.1:34315
export NO_PROXY=127.0.0.0/8
export no_proxy=127.0.0.0/8
node poc-no-proxy-cidr-axios.mjs
import http from 'http';
import axios from 'axios';
process.env.http_proxy = 'http://127.0.0.1:34315';
process.env.HTTP_PROXY = 'http://127.0.0.1:34315';
process.env.no_proxy = '127.0.0.0/8';
process.env.NO_PROXY = '127.0.0.0/8';
await axios.get('http://127.0.0.1:43993/metadata', { timeout: 2000 });

Exploit: (Educational Purposes!)

POC_INTERNAL_HOST=127.0.0.1 node poc-no-proxy-cidr-axios.mjs
NO_PROXY=127.0.0.0/8
HTTP_PROXY=http://127.0.0.1:34315
Target URL=http://127.0.0.1:43993/metadata
Response=proxy saw request for http://127.0.0.1:43993/metadata
Proxy hits=1
Internal direct hits=0
POC RESULT: axios sent the target through the proxy with NO_PROXY=127.0.0.0/8.
POC_INTERNAL_HOST=127.0.0.1 POC_NO_PROXY=127.0.0.1 node poc-no-proxy-cidr-axios.mjs
NO_PROXY=127.0.0.1
Response=internal service saw /metadata
Proxy hits=0
Internal direct hits=1
POC RESULT: axios bypassed the proxy with NO_PROXY=127.0.0.1.

Protection: from this CVE

export NO_PROXY=127.0.0.1,localhost,169.254.169.254
await axios.get(targetUrl, { proxy: false });

Use exact host/IP entries.

Patch when CIDR matching fixed.

Validate proxy trust boundary.

Impact:

Proxy exclusion bypass.

Requests to loopback, private, Kubernetes, CI, cloud metadata may traverse proxy.
Plaintext HTTP proxy can see and modify URLs, headers, bodies.
HTTPS proxy observes connection metadata and may receive CONNECT requests.
May expose request URLs, internal hostnames, paths, headers, credentials.

Not arbitrary proxy injection by itself.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top