Server-Side Request Forgery (SSRF) in axios - CVE-2025-62718
Published: April 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to conduct server-side request forgery and disclose sensitive information.
The vulnerability exists due to improper hostname normalization in NO_PROXY rule evaluation when processing attacker-controlled request URLs. A remote attacker can supply a crafted URL using forms such as localhost. or [::1] to conduct server-side request forgery and disclose sensitive information.
Applications that rely on NO_PROXY entries for loopback or internal services are affected.
Affected software
Langflow
Storage Sentinel Anomaly Scan Engine
Db2 Developer Extension
Rhapsody Systems Engineering
Db2 Big SQL
Maximo Application Suite - Monitor Component
Maximo Application Suite - Edge Data Collector
IBM supplied MQ Advanced container images
Rational Developer for i
IBM Maximo Scheduler Optimization
PowerVC
IBM MQ Operator
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Control
Jira Service Management Data Center
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
Confluence Data Center
Jira Software Data Center
IBM Business Automation Workflow
IBM Decision Optimization for Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Cloud Pak System
Fedora
Ubuntu
IBM Security SOAR
node-axios (Ubuntu package)
pgadmin4
nextcloud
How to mitigate CVE-2025-62718
Langflow - update to 1.9.0
Storage Sentinel Anomaly Scan Engine - update to 2.3.1
Db2 Developer Extension - update to 1.1.2
Rhapsody Systems Engineering - update to 1.8.0
IBM Cloud Pak System - update to 2.3.5.1
IBM MQ Operator - addressed in versions 3.2.26 SC2, 4.0.1 SC2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
IBM Spectrum Control - update to 5.5
Jira Service Management Data Center - addressed in versions 10.3.22, 11.3.7
IBM Sterling Secure Proxy - addressed in versions 6.1.0.4 iFix01, 6.2.1.2.iFix02
IBM Sterling External Authentication Server - update to 6.1.1.3 iFix01
Db2 Big SQL - update to 8.3.1 patch 4
Maximo Application Suite - Monitor Component - addressed in versions 8.10.30, 8.11.28, 9.0.20, 9.1.10
Maximo Application Suite - Edge Data Collector - addressed in versions 8.10.30, 8.11.28, 9.0.20, 9.1.10
Confluence Data Center - addressed in versions 9.2.22, 10.2.14
IBM supplied MQ Advanced container images - update to 10.0.0.0-r2
Rational Developer for i - update to 9.9.0.4
Jira Software Data Center - addressed in versions 10.3.22, 11.3.7
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
IBM Security SOAR - update to 51.0.10.0
node-axios (Ubuntu package) - addressed in versions 0.19.0+dfsg-2ubuntu0.1~esm1, 0.26.0+dfsg-1ubuntu0.1~esm1, 1.6.8+dfsg-2ubuntu0.1~esm1, 1.13.2+dfsg-1ubuntu0.1~esm1
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 6
IBM Maximo Scheduler Optimization - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
pgadmin4 - addressed in versions 9.14-3.fc42, 9.14-3.fc43, 9.14-3.fc44
App Connect Enterprise Certified Container - addressed in versions 12.0.23, 13.1.0
nextcloud - addressed in versions 33.0.3-1.el10_2, 33.0.3-1.el10_3, 33.0.3-1.fc42, 33.0.3-1.fc43, 33.0.3-1.fc44
External References
Related Security Bulletins
- Two vulnerabilities in Axios
- IBM Maximo Application Suite - Monitor Component update for Axios
- IBM Edge Data Collector update for Axios
- IBM PowerVC update for Axios
- IBM App Connect Enterprise Certified Container operands update for Axios
- Fedora 43 update for pgadmin4
- Fedora 42 update for pgadmin4
- Fedora 44 update for pgadmin4
- IBM Security SOAR update for Axios
- IBM Watson Discovery Cartridge update for Axios
- IBM Big SQL on Cloud Pak for Data update for Axios
- IBM Maximo Scheduler Optimization update for Axios
- Langflow OSS update for Axios
- Fedora 44 update for nextcloud
- Fedora 43 update for nextcloud
- Fedora EPEL 10.3 update for nextcloud
- Fedora EPEL 10.2 update for nextcloud
- Fedora 42 update for nextcloud
- Multiple vulnerabilities in Jira Service Management Data Center and Jira Service Management Server
- Multiple vulnerabilities in Jira Software Data Center
- Multiple vulnerabilities in IBM Decision Optimization for Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Spectrum Control
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Multiple vulnerabilities in Confluence Data Center
- Multiple vulnerabilities in IBM Rhapsody Systems Engineering
- Ubuntu update for node-axios
- Multiple vulnerabilities in IBM Rational Developer for i
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM Storage Sentinel Anomaly Scan Engine
- Multiple vulnerabilities in IBM Sterling External Authentication Server
- Multiple vulnerabilities in IBM Sterling Secure Proxy
- IBM Db2 Developer Extension update for Axios