CVE•Published 2026-04-24•Modified 2026-04-27•0 articles on news•5 live references•NVD data
CVE-2026-42043Axios · Axios
Vulnerability data via NVD (ingested)
CVSS v3.1
7.2
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
EPSS percentile
7
Exploit Prediction Scoring System · top 93% of all CVEs
Weaknesses (CWE)
Description
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This vulnerability is due to an incomplete for CVE-2025-62718, This vulnerability is fixed in 1.15.1 and 0.31.1.
Timeline
Published 2026-04-24
Modified 2026-04-27
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag11,079 hosts
vuln:CVE-2026-42043Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product
product:"Axios Axios"All exposed Axios Axios instances — cross-reference with the CVE's affected-version range.
Shodan · banner/body mention
http.html:"Axios"HTTP body or banner mentions "Axios" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2026-42043Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-42043Censys host search filtered to this CVE id.
grep.app
CVE-2026-42043Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-42043GitHub code search for direct mentions.
Google dork
"CVE-2026-42043" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub
No public proof-of-concept repositories found for CVE-2026-42043 on GitHub.
We haven't classified any articles referencing CVE-2026-42043 yet. The external references above still apply.