CVE-2025-27152

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-27152
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-27152.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-27152
Aliases
Related
Published
2025-03-07T16:15:38Z
Modified
2025-03-08T01:54:54.912382Z
Summary
[none]
Details

axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impacts both server-side and client-side usage of axios. This issue is fixed in 1.8.2.

References

Affected packages

Debian:11 / node-axios

Package

Name
node-axios
Purl
pkg:deb/debian/node-axios?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.21.1+dfsg-1
0.21.1+dfsg-1+deb11u1
0.21.3+dfsg-1
0.21.4+dfsg-1
0.22.0+dfsg-1
0.23.0+dfsg-1
0.23.0+dfsg-2
0.24.0+dfsg-1
0.25.0+dfsg-1
0.25.0+dfsg-2
0.26.0+dfsg-1
0.26.1+dfsg-1
0.26.1+dfsg-2
0.27.2+dfsg-1
0.27.2+dfsg-2

1.*

1.1.2+dfsg-1
1.1.2+dfsg-2
1.1.2+dfsg-3
1.1.3+dfsg-1
1.1.3+dfsg-2
1.2.0+dfsg-1
1.2.1+dfsg-1
1.5.1+dfsg-1
1.6.2+dfsg-1
1.6.8+dfsg-1
1.6.8+dfsg-2
1.7.3+dfsg-1
1.7.4+dfsg-1
1.7.7+dfsg-1
1.7.9+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / node-axios

Package

Name
node-axios
Purl
pkg:deb/debian/node-axios?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.2.1+dfsg-1
1.2.1+dfsg-1+deb12u1
1.5.1+dfsg-1
1.6.2+dfsg-1
1.6.8+dfsg-1
1.6.8+dfsg-2
1.7.3+dfsg-1
1.7.4+dfsg-1
1.7.7+dfsg-1
1.7.9+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / node-axios

Package

Name
node-axios
Purl
pkg:deb/debian/node-axios?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.2.1+dfsg-1
1.5.1+dfsg-1
1.6.2+dfsg-1
1.6.8+dfsg-1
1.6.8+dfsg-2
1.7.3+dfsg-1
1.7.4+dfsg-1
1.7.7+dfsg-1
1.7.9+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}