Vulnerability library
Security checkApril 16, 2026

Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmaxios

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the configured proxy.

Recommendation

Update the axios package to the latest compatible version. Followings are version details:

  • Affected version(s): **< 0.31.0 >= 1.0.0, < 1.15.0**
  • Patched version(s): **0.31.0 1.15.0**

References

Could your website be exposed too?

SmartScanner can check your website for Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated April 16, 2026