CVE-2025-62718Disclosure(axios / axios)

MEDIUMCVSS 9.9 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch axios axios systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the configured proxy. This goes against what developers expect and lets attackers force requests through a proxy, even if NO_PROXY is set up to protect loopback or internal services. This issue leads to the possibility of proxy bypass and SSRF vulnerabilities allowing attackers to reach sensitive loopback or internal services despite the configured protections. This vulnerability is fixed in 1.15.0 and 0.31.0.

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-441CWE-918CWE-1289

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • axios

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 15 mentions across 10 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 13 signals
  • Disclosure: 8 classified signals
  • Peaked 9d ago at 3 mentions (2026-04-09); latest day: 1
  • 15 total mentions across 10 days

Affected systems

Vendors
Products
axios

Deep dive

Activity timeline15 mentions / 10d
01223Mentions · 2026-04-09: 3Mentions · 2026-04-10: 3Mentions · 2026-04-11: 1Mentions · 2026-04-14: 2Mentions · 2026-04-24: 1Mentions · 2026-04-28: 1Mentions · 2026-04-30: 1Mentions · 2026-05-05: 1Mentions · 2026-05-29: 1Mentions · 2026-08-01: 1PoC Mentioned / Linked · 2026-04-10: 1PoC Mentioned / Linked · 2026-04-28: 1Active Exploitation · 2026-04-14: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-11: 1Patch / Workaround · 2026-04-14: 2Patch / Workaround · 2026-05-29: 1Technical Details · 2026-04-09: 3Technical Details · 2026-04-10: 2Technical Details · 2026-04-11: 1Technical Details · 2026-04-14: 2Technical Details · 2026-04-28: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-29: 1Technical Details · 2026-08-01: 104-0904-1004-1104-1404-2404-2804-3005-0505-2908-01
Signal classification5 categories
Disclosure
853.3%
Patch
213.3%
PoC
213.3%
General
213.3%
Active Exploitation
16.7%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-093
Disclosure3
2026-04-103
Disclosure1Patch1PoC1
2026-04-111
Patch1
2026-04-142
Active Exploitation1Disclosure1
2026-04-241
General1
2026-04-281
PoC1
2026-04-301
General1
2026-05-051
Disclosure1
2026-05-291
Disclosure1
2026-08-011
Disclosure1
Full discourse15 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    Axios CVE-2025-62718 allows a critical NO_PROXY bypass via hostname normalization errors. Protect your internal network from SSRF—patch or normalize today! #AxiosVulnerability #CyberSecurity #SSRF #InfoSec #NodeJS #WebDev https://securityonline.info/axios-no-proxy-hostname-normalization-bypass-cve-2025-62718/ https://t.co/U8wtJItO2r

    Post summary

    Axios CVE-2025-62718 is a critical SSRF vulnerability caused by NO_PROXY bypass via hostname normalization errors; users are urged to patch or normalize immediately.

    070153977
    12.3K followersView on X
  • Kruptos@KuptoKosmos
    PoC

    @PolymarketDevs 😉 c’est plus qu’un simple scrape public.. les PoC, la CVE-2025-62718 (CVSS 9.9), le bypass et accès à des endpoints non authentifiés montrent des faiblesses réelles dans la configuration API ! https://x.com/i/status/2049124170353594531

    Post summary

    The tweet announces a high‑severity CVE (CVE‑2025‑62718, CVSS 9.9) and confirms the existence of poC evidence that bypasses authentication to reach unauthenticated API endpoints.

    101614.9K
    8.5K followersView on X
  • つみかさね@tsumikasanedev
    Disclosure

    Node.jsで広く使われるAxiosに、NO_PROXY判定をすり抜けて内部サービスへ到達できるSSRF(CVE-2025-62718, CVSS9.9)。1.15.0未満/0.31.0未満が対象で、プロキシ保護をかけた内部エンドポイントに攻撃者が到達し得ます。

    Post summary

    The post announces a severe SSRF vulnerability in Axios, providing CVE details and affected versions, but no PoC, exploit code, or remediation information is discussed.

    1000047
    3 followersView on X
  • Shadowcat Labs@shadowcatLabs
    General

    Group(betwick, vicduong, Hisokaaa) claims Polymarket compromise: 1,609-user PII DB, hardcoded API keys, CVE-2025-62718, CVE-2025-27152, CVE-2024-51479, and alleges $2.5M insider trading on US-Iran markets.

    Post summary

    The message reports an alleged Polymarket compromise, citing a user PII database, hardcoded API keys, and three CVEs, but does not provide Proof of Concept, exploitation evidence, or mitigation guidance.

    00010647
    6 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-62718 Proxy Bypass and SSRF via Hostname Normalization in Axios Before 1.15.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-62718

    Post summary

    The text announces CVE‑2025‑62718, detailing a proxy bypass and SSRF flaw in Axios prior to version 1.15.0, but does not discuss PoC, exploitation, patches, or misinformation.

    00010354
    4.0K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - Two axios Security Flaws Disclosed (CVE-2026-44492 & CVE-2026-44494) Two high-severity vulnerabilities in axios (npm) were published today, both enabling network-level attacks by abusing proxy handling logic: axios NO_PROXY Bypass via IPv4-mapped IPv6 (CVE-2026-44492, CVSS 8.6) — shouldBypassProxy (introduced in v1.15.0 to fix CVE-2025-62718) fails to normalize IPv4-mapped IPv6 addresses like ::ffff:169.254.169.254. When NO_PROXY blocks 169.254.169.254, a request to its IPv6-mapped form still routes through the proxy, enabling cloud metadata SSRF against IMDS endpoints. axios Prototype Pollution → Full MITM via config.proxy (CVE-2026-44494, CVSS 9.4) — Because proxy is absent from axios defaults, the merged config object has no own proxy property. Any Object.prototype pollution in the dependency tree (e.g. via qs, minimist) can inject a malicious proxy into all axios HTTP requests, intercepting credentials, auth tokens, and response data with no user interaction and no visible indication. 👉 Affected: axios (npm) ≥ 1.0.0 < 1.16.0 and ≤ 0.31.1 | Upgrade to 1.16.0 / 0.32.0

    Post summary

    Two new high‑severity axios vulnerabilities, CVE‑2026‑44492 and CVE‑2026‑44494, have been disclosed, explaining how proxy handling flaws allow SSRF and MITM attacks; users are urged to upgrade to patched releases.

    0000070
    196 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Axios, NO_PROXY Loopback Bypass, #CVE-2025-62718 (Critical) https://dailycve.com/axios-no_proxy-loopback-bypass-cve-2025-62718-critical/

    Post summary

    The tweet announces the critical CVE-2025-62718, a NO_PROXY loopback bypass vulnerability, referencing an external article while lacking details on exploitation, patches, or PoC.

    00000525
    191 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2025-62718 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/465 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The tweet confirms CVE‑2025‑62718 is no longer present in the latest AWS Lambda base images, but offers no additional details or mitigation steps.

    00000507
    31 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    CVSS 9.3: Axios CVE-2025-62718 is under active exploitation—hackers can manipulate server requests, potentially exposing sensitive data. Patch now to safeguard your systems. #NerdieNews #CyberSecurity #InfoSec #ZeroDay #DataBreach #Adobe #Apple https://t.co/ngtPLj409P

    Post summary

    The tweet announces that CVE‑2025‑62718 (CVSS 9.3) is currently being exploited to manipulate server requests and expose sensitive data, urging immediate patching.

    00000194
    55 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A NO_PROXY hostname normalization bypass (CVE-2025-62718) in `Axios` could lead to SSRF. Implement strict input validation and monitor for patches. #Axios #SSRF #infosec https://www.pulsepatch.io/posts/cve-2025-62718-axios-ssrf-bypass

    Post summary

    The post discusses a NO_PROXY hostname normalization bypass (CVE-2025-62718) in Axios that could enable SSRF, recommending strict input validation and monitoring for patches, but does not provide exploit code or evidence of active exploitation.

    00000469
    11 followersView on X
  • Vulert@vulert_official
    Patch

    🚨 Critical Axios flaw: CVE-2025-62718 A NO_PROXY hostname normalization bypass could expose internal services and weaken proxy-based protections. Update to the patched version now. 🔗 https://vulert.com/vuln-db/CVE-2025-62718 #CyberSecurity #Axios #CVE202562718 #Vulert https://t.co/TCbiiUdB2V

    Post summary

    The tweet announces a critical Axios flaw (CVE‑2025‑62718) that bypasses NO_PROXY hostname normalization and exposes internal services, and urges users to apply the available patch.

    00000480
    124 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼ #Axios: disponibile #PoC per lo sfruttamento della CVE-2025-62718, presente nella nota libreria open source Rischio: 🔴 Tipologia: 🔸 Information Disclosure 🔸 Spoofing 🔗 https://www.acn.gov.it/portale/w/disponibile-poc-per-lo-sfruttamento-della-cve-2025-62718-nella-libreria-axios ⚠ Importante mantenere aggiornati i sist… https://t.co/SKMILqsVR7

    Post summary

    The tweet announces that a proof of concept for CVE-2025-62718 is available and links to it, but it does not mention exploitation tools, active attacks, patches, or debunking.

    00000405
    605 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New CRITICAL CVE detected in AWS Lambda 🚨 CVE-2025-62718 impacts axios in 4 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/465 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    The tweet announces a critical CVE (CVE-2025-62718) affecting AWS Lambda base images, linking to a GitHub issue and a website for additional details.

    00000355
    31 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-62718 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules… https://www.cve.org/CVERecord?id=CVE-2025-62718

    Post summary

    CVE-2025-62718 is disclosed as a flaw in Axios (pre‑1.15.0) where hostname normalization mis‑applies NO_PROXY rules; no PoC, exploit, workaround, or active exploitation is reported.

    00000535
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-62718: Axios has a NO_PROXY Hostname No... Hostname normalization bypass in Axios lets attackers proxy-hop past NO_PROXY protections with trailing dots and IPv6 l... https://zerodaysignal.com/vulnerability/CVE-2025-62718 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2025‑62718 reveals an Axios hostname normalization bypass that allows proxy‑hopping past NO_PROXY restrictions using trailing dots and IPv6. The post provides technical details but does not offer a PoC, exploit, patch, or evidence of active exploitation.

    00000472
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appaxiosaxios-node.js-

Explore more