logo

Critical SSRF Flaw Discovered in Axios – CVE-2025-62718 (CVSS 9.3)

ID: 291f70fc-02ec-59c7-aa82-1be26b8e3a0f

STIX ID: report--291f70fc-02ec-59c7-aa82-1be26b8e3a0f

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-04-14

Date Updated: 2026-04-23

Author: Ddos

...
...

Axios vulnerability CVE-2025-62718 (CVSS 9.3) allows NO_PROXY matching to be bypassed due to missing hostname normalization (examples: `localhost.` and IPv6 loopback `[::1]`), which can lead to SSRF, mitigation bypass, and sensitive data exfiltration; confirmed in Axios 1.12.2, developers are urged to audit NO_PROXY usage, apply patches, or manually normalize URLs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.