Improper Isolation or Compartmentalization Affecting axios package, versions >=1.15.0 <1.20.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-AXIOS-20341520
  • published1 Oct 2026
  • disclosed30 Sept 2026
  • creditMcDubh

Introduced: 30 Sep 2026

NewCVE-2026-101899  (opens in a new tab)
CWE-653  (opens in a new tab)

How to fix?

Upgrade axios to version 1.20.0 or higher.

Overview

axios is a promise-based HTTP client for the browser and Node.js.

Affected versions of this package are vulnerable to Improper Isolation or Compartmentalization in lib/helpers/shouldBypassProxy.js, which matches NO_PROXY entries by exact host or IP and has no parsing for CIDR notation, so an entry such as 127.0.0.0/8 or 10.0.0.0/8 never matches and the request is routed through the configured proxy. An attacker able to observe or operate that proxy can read internal hostnames, request URLs, headers, and any credentials those requests carry, by receiving traffic the deployment intended to keep direct. This requires a Node.js deployment with HTTP_PROXY or HTTPS_PROXY set, at least one NO_PROXY entry written in CIDR form, and a proxy sitting outside the intended trust boundary, and exact host or IP entries in NO_PROXY are matched correctly.

Note: This is only exploitable when requests are configured with proxy: false.

Workaround

This vulnerability can be avoided by writing NO_PROXY entries for sensitive destinations as exact hosts or IP addresses rather than CIDR ranges.

CVSS Base Scores

version 4.0
version 3.1