HomeCyber BalkansAxios Vulnerabilities Allow Attackers to Evade Proxy Controls and Execute SSRF Attacks

Axios Vulnerabilities Allow Attackers to Evade Proxy Controls and Execute SSRF Attacks

Published on

spot_img

Security Vulnerabilities Disclosed in Axios: A Comprehensive Overview

Axios maintainers have recently reported a series of significant security vulnerabilities that could have dire consequences for server-side applications. These high-severity vulnerabilities risk allowing malicious actors to bypass both proxy and DNS settings, which could enable server-side request forgery (SSRF) attacks targeting internal services and cloud metadata endpoints. The implications of these vulnerabilities are vast, posing risks not just to individual applications but potentially compromising entire enterprise networks.

The most pressing issue identified, tracked under the identifier GHSA-3pq3-5fj3-cg6v, is linked to the HTTP/2 request path within Axios. This vulnerability emerges because the HTTP/2 adapter establishes sessions using the method http2.connect() and relies solely on the options.http2Options. This design oversight means critical top-level Axios settings, including custom DNS lookup handlers, agents, and proxy configurations, are overlooked. As a result, requests that developers expect to route through defined proxies could very well connect directly to their intended destinations without any monitoring or restriction.

This flaw is especially concerning for applications that permit user input regarding outbound URLs, enable Axios’s HTTP/2 support, and utilize proxies or custom DNS resolvers for protection against SSRF vulnerabilities. An attacker could exploit this weakness by supplying a URL that targets an internal hostname, private IP address, or even a cloud metadata service. If an application’s security relies on Axios for proxy routing or a custom lookup function designed to block sensitive requests, the HTTP/2 execution route might circumvent these controls, establishing a direct link without the necessary security protocols in place.

According to Axios’s advisory, this vulnerability notably impacts server-side deployments where Axios functions as an outbound HTTP client and where network security controls are implemented at the library configuration layer. Successful exploitation of this weakness could expose sensitive internal API responses, credentials, cloud instance metadata, or administrative interfaces. Moreover, it poses the risk of permitting unauthorized state-changing requests to services that would otherwise remain protected.

The identified HTTP/2 vulnerability affects specific versions of Axios, namely versions ranging from 1.13.0 through 1.20.0. Fortunately, a fix was introduced in version 1.20.0, addressing these vulnerabilities, according to vulnerability tracking data.

In addition to the HTTP/2 issues, several other proxy-handling weaknesses were uncovered in Axios, jeopardizing the effectiveness of SSRF defenses reliant on environment variables like HTTP_PROXY, HTTPS_PROXY, and NO_PROXY. One notable advisory, GHSA-44g4-m2mj-wpvx, specifies that Axios does not acknowledge CIDR-form entries in NO_PROXY. Such entries are often utilized by organizations to prevent proxying of traffic for private subnets, including ranges like 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. The failure of Axios to apply these exclusions could significantly weaken established proxy-routing policies and compromise defense-in-depth strategies.

The vulnerabilities disclosed include a range of CVEs, each associated with varying types of hazards. For instance, CVE-2026-101901 pertains to an unhandled error event in the initialization process of HTTP/2 ClientHttp2Session, while CVE-2026-101898 refers to the HTTP/2 adapter’s failure to respect custom DNS lookups and proxy settings. Other related vulnerabilities, while varied in nature, further underscore a troubling trend that potential attackers could exploit.

Historically, several vulnerabilities in Axios have also connected to hostname normalization and edge cases involving IP addresses. For instance, certain malformed representations of loopback addresses, such as localhost. or IPv6 literals, have been known to escape No_PROXY checks, forcing traffic through a configured proxy. Further complicating matters, the address 0.0.0.0 has been mishandled in certain Axios versions (1.15.0 through 1.16.1), failing to classify it as local during NO_PROXY evaluations. This mishap allows potential attackers to redirect requests unexpectedly.

In light of these disclosures, security teams are urged to promptly inventory their Node.js applications that utilize Axios for outbound requests. This is especially crucial for applications that fetch user-supplied URLs, process webhooks, or integrate with cloud services. The situation reveals the ongoing risks present in outbound request security; it’s essential that proxy settings and URL validations are universally applied across all protocol adapters, redirect paths, DNS resolution processes, and address representations.

As developers and organizations grapple with these vulnerabilities, the importance of rigorous security measures cannot be overstated. Recognizing these vulnerabilities is the first step, but actively addressing and remediating them is imperative for maintaining secure server-side applications.

Source link

Latest articles

Treasury Issues Blacklist for ATM Malware Developer

The United States Treasury Department has recently taken decisive action by imposing sanctions on...

ThreatsDay: AI-Driven Zero-Day Chain, 543K Active Secrets, Model Inspection RCE, and 13 Additional Stories

This week, cybersecurity experts highlighted the significance of seemingly mundane terms like inspect, cache,...

Spain Arrests Teen Suspected in KillSec Ransomware Case

Three Arrested as Police Seize Ransomware Leak Site; U.S. Charges Dutch Suspect On October 1,...

MI5 Warns That Over 100 Academics Aided China’s Espionage Efforts

The UK’s domestic security agency, MI5, has issued an alarming alert regarding academic collaborations...

More like this

Treasury Issues Blacklist for ATM Malware Developer

The United States Treasury Department has recently taken decisive action by imposing sanctions on...

ThreatsDay: AI-Driven Zero-Day Chain, 543K Active Secrets, Model Inspection RCE, and 13 Additional Stories

This week, cybersecurity experts highlighted the significance of seemingly mundane terms like inspect, cache,...

Spain Arrests Teen Suspected in KillSec Ransomware Case

Three Arrested as Police Seize Ransomware Leak Site; U.S. Charges Dutch Suspect On October 1,...