axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade node-axios | Jul 27, 2026 | Jul 27, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 17, 2026 | Aug 12, 2024 |
| Suse | — | Upgrade velociraptorUpgrade system-user-velociraptorUpgrade velociraptor-clientUpgrade pgadmin4-web-uwsgiUpgrade pgadmin4Upgrade system-user-pgadminUpgrade pgadmin4-desktopUpgrade pgadmin4-docUpgrade pgadmin4-cloud | Dec 5, 2025 | Oct 29, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub