MEDIUM GitHub
CVE-2026-101899
Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges
## Summary
Axios supports proxy environment variables and evaluates `NO_PROXY` exclusions in the Node.js adapter. CIDR-form `NO_PROXY` entries such as `127.0.0.0/8`, `10.0.0.0/8`, or `169.254.169.254/32` are not interpreted as IP ranges. As a result, a request to an IP address inside a configured CIDR exclusion can still be sent through the configured proxy.
This affects deployments that rely on CIDR notation to keep loopback, private, Kubernetes, CI, or cloud metadata traffic away from proxy
Affected Products
- npm/axios >= 1.15.0, < 1.20.0
References
- https://github.com/advisories/GHSA-44g4-m2mj-wpvx
- https://github.com/axios/axios/security/advisories/GHSA-44g4-m2mj-wpvx
- https://github.com/axios/axios/pull/11141
- https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a
This medium severity vulnerability was published on 2026-09-30 via GitHub. Affected: npm/axios >= 1.15.0, < 1.20.0.
vulnfeed aggregates 9504 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.