Security vulnerabilities and automated fixes for no proxy issues
1 post found
CVE-2026-42043 is a high-severity vulnerability in axios where malformed URLs circumvent NO_PROXY environment variable protections, causing internal requests to route through attacker-controlled proxies. The fix upgrades axios from 1.13.6 to 1.18.0, introducing stricter proxy agent handling with `https-proxy-agent` and updated `follow-redirects`.