Server-Side Request Forgery (SSRF) in axios - CVE-2025-62718

 

Server-Side Request Forgery (SSRF) in axios - CVE-2025-62718

Published: April 10, 2026


Vulnerability identifier: #VU125750
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:L/SI:N/SA:N]
CVE-ID: CVE-2025-62718
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conduct server-side request forgery and disclose sensitive information.

The vulnerability exists due to improper hostname normalization in NO_PROXY rule evaluation when processing attacker-controlled request URLs. A remote attacker can supply a crafted URL using forms such as localhost. or [::1] to conduct server-side request forgery and disclose sensitive information.

Applications that rely on NO_PROXY entries for loopback or internal services are affected.


Affected software

axios
Langflow
Storage Sentinel Anomaly Scan Engine
Db2 Developer Extension
Rhapsody Systems Engineering
Db2 Big SQL
Maximo Application Suite - Monitor Component
Maximo Application Suite - Edge Data Collector
IBM supplied MQ Advanced container images
Rational Developer for i
IBM Maximo Scheduler Optimization
PowerVC
IBM MQ Operator
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Control
Jira Service Management Data Center
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
Confluence Data Center
Jira Software Data Center
IBM Business Automation Workflow
IBM Decision Optimization for Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Cloud Pak System
Fedora
Ubuntu
IBM Security SOAR
node-axios (Ubuntu package)
pgadmin4
nextcloud

How to mitigate CVE-2025-62718

Install security update from vendor's website.

axios - update to 1.15.0
Langflow - update to 1.9.0
Storage Sentinel Anomaly Scan Engine - update to 2.3.1
Db2 Developer Extension - update to 1.1.2
Rhapsody Systems Engineering - update to 1.8.0
IBM Cloud Pak System - update to 2.3.5.1
IBM MQ Operator - addressed in versions 3.2.26 SC2, 4.0.1 SC2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
IBM Spectrum Control - update to 5.5
Jira Service Management Data Center - addressed in versions 10.3.22, 11.3.7
IBM Sterling Secure Proxy - addressed in versions 6.1.0.4 iFix01, 6.2.1.2.iFix02
IBM Sterling External Authentication Server - update to 6.1.1.3 iFix01
Db2 Big SQL - update to 8.3.1 patch 4
Maximo Application Suite - Monitor Component - addressed in versions 8.10.30, 8.11.28, 9.0.20, 9.1.10
Maximo Application Suite - Edge Data Collector - addressed in versions 8.10.30, 8.11.28, 9.0.20, 9.1.10
Confluence Data Center - addressed in versions 9.2.22, 10.2.14
IBM supplied MQ Advanced container images - update to 10.0.0.0-r2
Rational Developer for i - update to 9.9.0.4
Jira Software Data Center - addressed in versions 10.3.22, 11.3.7
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
IBM Security SOAR - update to 51.0.10.0
node-axios (Ubuntu package) - addressed in versions 0.19.0+dfsg-2ubuntu0.1~esm1, 0.26.0+dfsg-1ubuntu0.1~esm1, 1.6.8+dfsg-2ubuntu0.1~esm1, 1.13.2+dfsg-1ubuntu0.1~esm1
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 6
IBM Maximo Scheduler Optimization - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
pgadmin4 - addressed in versions 9.14-3.fc42, 9.14-3.fc43, 9.14-3.fc44
App Connect Enterprise Certified Container - addressed in versions 12.0.23, 13.1.0
nextcloud - addressed in versions 33.0.3-1.el10_2, 33.0.3-1.el10_3, 33.0.3-1.fc42, 33.0.3-1.fc43, 33.0.3-1.fc44

External References

Related Security Bulletins