Vulnerability DatabaseCVE-2026-101899

CVE-2026-101899: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-101899 is a proxy exclusion bypass vulnerability in the Axios npm library affecting its Node.js adapter. The flaw causes CIDR-notation entries in the NO_PROXY environment variable (e.g., 127.0.0.0/8, 10.0.0.0/8, 169.254.169.254/32) to be silently ignored, routing traffic intended to bypass the proxy through the configured proxy instead. Affected versions are >= 1.15.0, < 1.20.0 (npm package axios); browser adapters are not affected. The advisory was published on September 16, 2026, and added to the GitHub Advisory Database on September 30, 2026. It carries a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, Axios Security Advisory).

Technical details

The root cause is a Protection Mechanism Failure (CWE-693) in lib/helpers/shouldBypassProxy.js. The function parses each NO_PROXY entry into a host and optional port, then performs exact hostname, suffix, wildcard-prefix, and loopback comparisons — but contains no logic to parse or evaluate CIDR notation. As a result, an entry like 127.0.0.0/8 is treated as a literal hostname token that never matches any request target IP, causing all requests to IPs within that range to be forwarded through the configured proxy. The vulnerability is exploitable whenever an application runs in a Node.js environment with both HTTP_PROXY/HTTPS_PROXY and CIDR-form NO_PROXY environment variables set; no privileges or user interaction are required, though a proxy must already be configured (Attack Requirements: Present). A public proof-of-concept demonstrating the bypass is included in the advisory (GitHub Advisory, Axios Security Advisory).

Impact

The primary impact is confidentiality exposure on downstream/subsequent systems (rated High in CVSS v4.0), with no direct impact on the vulnerable system itself. For plaintext HTTP targets, a proxy positioned outside the intended trust boundary can observe and modify request URLs, headers, and bodies — potentially exposing internal hostnames, API paths, authentication tokens, or credentials. For HTTPS targets, the proxy receives CONNECT tunnel requests and observes connection metadata. Environments most at risk include CI/CD runners with injected proxy variables, Kubernetes workloads using CIDR-based NO_PROXY for cluster-internal ranges, containers inheriting proxy settings from orchestrators, and cloud workloads relying on NO_PROXY to protect access to instance metadata services (e.g., 169.254.169.254) (GitHub Advisory, Axios Security Advisory).

Exploitability

A public proof-of-concept is included in the official advisory and can be reproduced with a simple Node.js script using standard http and axios modules. There is no evidence of in-the-wild exploitation reported at this time, no known threat actor attribution, and the CVE status remains "Reserved" in the NVD. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a pre-existing proxy configuration in the target environment, limiting opportunistic exploitation, but the condition is common in enterprise, CI/CD, and cloud-native deployments (GitHub Advisory, Axios Security Advisory).

Exploitation steps

  1. Identify a vulnerable deployment: Locate a Node.js application using axios >= 1.15.0, < 1.20.0 in an environment where HTTP_PROXY or HTTPS_PROXY is set and NO_PROXY contains CIDR-notation entries (e.g., NO_PROXY=10.0.0.0/8 or NO_PROXY=169.254.169.254/32).
  2. Position a proxy: Ensure control of or access to the configured proxy server (e.g., a compromised corporate proxy, a misconfigured shared proxy, or an attacker-controlled proxy injected via environment variable manipulation).
  3. Trigger a request to a CIDR-excluded IP: Cause the vulnerable application to make an HTTP/HTTPS request to an IP address that falls within the CIDR range listed in NO_PROXY — for example, a request to http://169.254.169.254/latest/meta-data/ (cloud metadata) or an internal Kubernetes service IP.
  4. Observe proxy interception: Because axios does not parse the CIDR notation, shouldBypassProxy() returns false for the target IP, and the request is routed through the configured proxy. The proxy receives the full request including URL, headers, and body.
  5. Extract sensitive data: From the proxy logs or intercepted traffic, collect exposed information such as internal service URLs, authentication headers, API keys, or cloud instance metadata credentials (GitHub Advisory, Axios Security Advisory).

Indicators of compromise

  • Network: Unexpected HTTP CONNECT or plaintext HTTP requests from application servers to a proxy server destined for internal IP ranges (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 127.0.0.0/8, 169.254.169.254); proxy access logs showing requests to cloud metadata endpoints (169.254.169.254) or Kubernetes cluster-internal IPs routed through the proxy.
  • Logs: Proxy server access logs containing entries for internal hostnames or RFC-1918/loopback addresses that should have been excluded by NO_PROXY policy; application logs showing successful responses from internal services via proxy rather than direct connection.
  • Environment: Presence of HTTP_PROXY/HTTPS_PROXY environment variables alongside CIDR-form NO_PROXY entries in Node.js process environments running axios >= 1.15.0, < 1.20.0.

Mitigation and workarounds

Upgrade axios to version 1.20.0 or later, which adds full IPv4 and IPv6 CIDR matching to NO_PROXY/no_proxy in the shouldBypassProxy helper (Axios v1.20.0 Release, Fix PR #11141). If immediate upgrade is not possible, apply the following workarounds:

  • Replace CIDR entries in NO_PROXY with explicit exact IP or hostname entries for all sensitive destinations (e.g., NO_PROXY=127.0.0.1,localhost,169.254.169.254,10.0.0.1,...).
  • For individual requests that must not traverse a proxy, set proxy: false in the axios request configuration.
  • Audit all Node.js deployments using axios in environments with injected proxy variables to identify reliance on CIDR-form NO_PROXY entries (GitHub Advisory).

Community reactions

The advisory was published by axios maintainer jasonsaayman on September 16, 2026, and the fix was merged via PR #11141 on August 12, 2026, ahead of the public disclosure. The fix was bundled into the v1.20.0 release on August 19, 2026. Downstream projects such as icanbwell/fhir-server and open-metadata/OpenMetadata promptly bumped their axios dependency to ^1.20.0 following the advisory publication. No significant independent researcher commentary or broad media coverage has been identified at this time (Axios v1.20.0 Release, Fix PR #11141).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management