OVERVIEW CVE-2025-62718 affects Axios, a widely-used HTTP client library for Node.js and browser environments. The vulnerability exists in versions prior to 1.15.0 and 0.31.0 and involves improper hostname normalization when processing NO_PROXY rules. Attackers can bypass proxy protections by crafting requests to loopback addresses in non-standard formats, such as localhost with a trailing dot or IPv6 literals, allowing traffic to reach internal services that should be protected. SEVERITY This critical vulnerability carries a CVSS score of 9.9, indicating maximum severity. The attack requires no authentication or user interaction and can be executed over the network with low complexity. The vulnerability enables proxy bypass and Server-Side Request Forgery (SSRF) attacks with high confidentiality impact, low integrity impact, and low availability impact across connected systems. Organizations using Axios without immediate patching face exposure of sensitive loopback and internal services to remote exploitation. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, and this vulnerability is not listed on the Known Exploited Vulnerabilities catalog. The EPSS score of 0.0004 indicates minimal current exploitation likelihood, though this may increase as awareness spreads. Immediate patching to versions 1.15.0 or 0.31.0 is recommended, particularly for applications exposing Axios functionality in network-accessible services.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.31.0CPE matchmatch criteria | cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:* | ||
>= 1.0.0, < 1.15.0CPE matchmatch criteria | cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.