CVE-2026-101899

MEDIUMCVSS · not yet scored
—
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • No CVSS published and no exploitation signals yet
CISA-KEV: Not listedEPSS PROB: —CVSS v2: —Exploit: None knownExposed services: Not assessed

No fix is confirmed yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for the fix.

Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges

Summary

Axios supports proxy environment variables and evaluates NO_PROXY exclusions in the Node.js adapter. CIDR-form NO_PROXY entries such as 127.0.0.0/8, 10.0.0.0/8, or 169.254.169.254/32 are not interpreted as IP ranges. As a result, a request to an IP address inside a configured CIDR exclusion can still be sent through the configured proxy.

This affects deployments that rely on CIDR notation to keep loopback, private, Kubernetes, CI, or cloud metadata traffic away from proxy infrastructure.

Impact

If the configured proxy is outside the intended trust boundary, requests that operators expected to bypass the proxy may be exposed to it. For plaintext HTTP targets, the proxy can see and modify URLs, headers, and bodies. For HTTPS targets, the proxy still observes connection metadata and may receive CONNECT requests that policy expected to avoid.

This is a proxy exclusion bypass, not arbitrary proxy injection by itself.

Affected Functionality

Affected:

  • Node.js adapter proxy environment handling.
  • HTTP_PROXY, HTTPS_PROXY, NO_PROXY, or lowercase equivalents.
  • CIDR entries in NO_PROXY.

Not affected:

  • Exact host or exact IP NO_PROXY entries where axios matching succeeds.
  • Requests configured with proxy: false.
  • Browser adapters.

Technical Details

lib/helpers/shouldBypassProxy.js parses each NO_PROXY entry into a host and optional port, normalizes hostnames, and then compares exact hostnames, suffix entries, wildcard-prefix entries, and loopback equivalents. It does not parse CIDR notation.

Local verification on axios 1.18.1:

process.env.NO_PROXY = '127.0.0.0/8';
shouldBypassProxy('http://127.0.0.1:1234/'); // false

The expected result for CIDR-aware bypass policy is true.

Proof of Concept of Attack

Constrained local demonstration:

  • Set HTTP_PROXY=http://127.0.0.1:.
  • Set NO_PROXY=127.0.0.0/8.
  • Request http://127.0.0.1:/metadata.
  • Observe that axios sends the request through the proxy instead of directly to the internal listener.

Workarounds

Use exact host or IP entries in NO_PROXY for sensitive destinations until CIDR matching is fixed, for example 127.0.0.1,localhost,169.254.169.254. For individual requests that must not use a proxy, set proxy: false.

Original report

Summary

Axios 1.17.0 honors HTTP_PROXY / HTTPS_PROXY and supports NO_PROXY host exclusions, but CIDR-form NO_PROXY entries such as 127.0.0.0/8 are not treated as network ranges. As a result, requests to IPs covered by a configured CIDR exclusion may still be sent through the configured proxy.

In the attached PoC, a request to 127.0.0.1 is sent through HTTP_PROXY despite NO_PROXY=127.0.0.0/8.

This can cause proxy exclusion bypass in environments where operators use CIDR notation to exclude loopback, private, internal, Kubernetes, CI, or cloud metadata address ranges from proxying.

Details

Axios supports proxy environment variables, including HTTP_PROXY / HTTPS_PROXY and NO_PROXY-style exclusions. Axios’s threat model treats environment proxy handling as security-relevant and lists NO_PROXY as a mitigation for proxy environment variable hijack, including hardening for CIDR ranges, IPv6 literals, and wildcard patterns. See: https://github.com/axios/axios/blob/a8e4f13aeecc45a3b8fab3ecfd9ddb5d70fb772b/THREATMODEL.md#t-r9-proxy-environment-variable-hijack

The issue is that CIDR-form NO_PROXY entries are not interpreted as network ranges. For example:

NO_PROXY=127.0.0.0/8
HTTP_PROXY=http://127.0.0.1:
Target URL=http://127.0.0.1:/metadata

Since 127.0.0.1 is inside 127.0.0.0/8, an operator may reasonably expect Axios to bypass the proxy for this request. Instead, Axios sends the request through HTTP_PROXY.

This appears to affect the proxy bypass decision path used for NO_PROXY / no_proxy handling. The relevant behavior is in Axios's Node proxy handling and NO_PROXY evaluation logic, including the shouldBypassProxy helper introduced for no_proxy hostname normalization and bypass checks.

The issue is not that Axios ignores NO_PROXY entirely. Exact host exclusions work. The issue is specifically that CIDR-form exclusions are silently treated as non-matching host/domain tokens rather than as network ranges, causing the request to be proxied.

This is security-relevant because CIDR notation is commonly used in container, CI, enterprise proxy, and cloud environments for ranges such as:

127.0.0.0/8
10.0.0.0/8
172.16.0.0/12
192.168.0.0/16
169.254.169.254/32

If operators rely on those entries to prevent internal or metadata-style requests from traversing a proxy, Axios may violate that expectation.

PoC

import http from 'http';
import axios from 'axios';

function listen(server, host) { return new Promise((resolve, reject) => { server.once('error', reject); server.listen(0, host, () => resolve(server.address().port)); }); }

function close(server) { return new Promise((resolve) => server.close(resolve)); }

let proxyHits = 0; let internalHits = 0;

const internal = http.createServer((req, res) => { internalHits += 1; res.writeHead(200, { 'content-type': 'text/plain' }); res.end(internal service saw ${req.url}); });

const proxy = http.createServer((req, res) => { proxyHits += 1; res.writeHead(200, { 'content-type': 'text/plain' }); res.end(proxy saw request for ${req.url}); });

const internalHost = process.env.POC_INTERNAL_HOST || '127.0.0.2'; const proxyHost = process.env.POC_PROXY_HOST || '127.0.0.1';

let internalPort; let proxyPort;

try { internalPort = await listen(internal, internalHost); proxyPort = await listen(proxy, proxyHost); } catch (error) { console.error('Failed to bind local PoC servers.'); console.error('On some systems 127.0.0.2 is unavailable; try:'); console.error(' POC_INTERNAL_HOST=127.0.0.1 node poc-no-proxy-cidr-axios.mjs'); console.error(''); throw error; }

const targetUrl = http://${internalHost}:${internalPort}/metadata; const proxyUrl = http://${proxyHost}:${proxyPort}; const noProxy = process.env.POC_NO_PROXY || '127.0.0.0/8';

process.env.http_proxy = proxyUrl; process.env.HTTP_PROXY = proxyUrl; process.env.no_proxy = noProxy; process.env.NO_PROXY = noProxy;

console.log('Axios NO_PROXY CIDR full axios network PoC'); console.log(axios VERSION=${axios.VERSION || 'unknown'}); console.log(NO_PROXY=${process.env.no_proxy}); console.log(HTTP_PROXY=${process.env.http_proxy}); console.log(Target URL=${targetUrl}); console.log('');

try { const response = await axios.get(targetUrl, { timeout: 2000, });

console.log(Response=${response.data}); console.log(Proxy hits=${proxyHits}); console.log(Internal direct hits=${internalHits}); console.log('');

if (proxyHits > 0 && internalHits === 0) { console.log(POC RESULT: axios sent the target through the proxy with NO_PROXY=${noProxy}.); } else if (proxyHits === 0 && internalHits > 0) { console.log(POC RESULT: axios bypassed the proxy with NO_PROXY=${noProxy}.); } else { console.log('POC RESULT: mixed/ambiguous routing; inspect counts above.'); } } finally { delete process.env.http_proxy; delete process.env.HTTP_PROXY; delete process.env.no_proxy; delete process.env.NO_PROXY; await close(proxy); await close(internal); }

Run the failing CIDR case:

POC_INTERNAL_HOST=127.0.0.1 node poc-no-proxy-cidr-axios.mjs

Observed:

Axios NO_PROXY CIDR full axios network PoC
axios VERSION=1.17.0
NO_PROXY=127.0.0.0/8
HTTP_PROXY=http://127.0.0.1:34315
Target URL=http://127.0.0.1:43993/metadata

Response=proxy saw request for http://127.0.0.1:43993/metadata Proxy hits=1 Internal direct hits=0

POC RESULT: axios sent the target through the proxy with NO_PROXY=127.0.0.0/8.

Control

Axios does honor exact IP NO_PROXY entries:

POC_INTERNAL_HOST=127.0.0.1 POC_NO_PROXY=127.0.0.1 node poc-no-proxy-cidr-axios.mjs

Expected:

NO_PROXY=127.0.0.1
Response=internal service saw /metadata
Proxy hits=0
Internal direct hits=1

POC RESULT: axios bypassed the proxy with NO_PROXY=127.0.0.1.

This shows the issue is not that NO_PROXY is ignored entirely. The bypass failure is specific to CIDR-form entries such as 127.0.0.0/8.

Impact

This is a proxy exclusion bypass caused by unsupported CIDR matching in NO_PROXY.

The impact is configuration-dependent. It affects Axios users in Node.js environments who rely on proxy environment variables and configure NO_PROXY using CIDR notation to exclude internal, loopback, private, Kubernetes, CI, or cloud metadata ranges.

Potentially impacted environments include:

  • CI/CD runners with globally injected HTTP_PROXY / HTTPS_PROXY.
  • Containers inheriting proxy variables from the host or orchestrator.
  • Kubernetes workloads using NO_PROXY for cluster-internal service ranges.
  • Enterprise networks using HTTP proxies with internal network exclusions.
  • Cloud workloads relying on NO_PROXY to keep metadata or internal service requests off proxy infrastructure.

If a configured proxy is compromised, attacker-controlled, overly broad, or outside the intended trust boundary, requests that operators expected to stay direct may instead be exposed to that proxy. This may expose request URLs, internal hostnames, paths, headers, or credentials depending on application behavior.

This should not be characterized as arbitrary proxy injection by itself. The issue is that Axios silently fails to enforce common CIDR-form proxy exclusions, which can undermine proxy bypass policy and defense-in-depth assumptions.


CVSS v3
—
EchelonGraph score
Not yet assessedNo source has published severity data for this CVE yet — no CVSS score from NVD or a CNA, no GitHub advisory, and it is not in CISA KEV. This is not a rating of zero; we cannot assess it yet.
EG Score
—
EG Risk
—
EPSS PROB
—
EPSS %ILE
—
KEV
Not listed

Published

September 30, 2026

Last Modified

September 30, 2026

Vendor Advisories for CVE-2026-101899(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Affected Packages

(1 across 1 ecosystem)
npm(1)
PackageVulnerable rangeFix by version rangeDependents
axios—
  • 1.15.0 up to 1.20.0: fixed in 1.20.0
—

Data Freshness Timeline

(refreshed 1× in last 7d / 1× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-09-30 16:12 UTCEG score recompute

Frequently asked(3)

What is CVE-2026-101899?
CVE-2026-101899 is a medium vulnerability published on September 30, 2026. Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges Summary Axios supports proxy environment variables and evaluates NOPROXY exclusions in the Node.js adapter. CIDR-form NOPROXY entries such as 127.0.0.0/8, 10.0.0.0/8, or 169.254.169.254/32 are not…
When was CVE-2026-101899 disclosed?
CVE-2026-101899 was first published on September 30, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
How do I remediate CVE-2026-101899?
No fix for CVE-2026-101899 is confirmed yet. Until one is published, restrict network exposure of the affected system or apply the vendor's mitigation — for example, keep it off the internet or limit it to trusted networks — and watch the vendor's advisory for the fix. The vendor advisories EchelonGraph has for CVE-2026-101899 are linked in the Vendor Advisories panel on this page.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-101899

Explore →

Is Your Infrastructure Affected by CVE-2026-101899?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.