Red Hat Security Advisory: Network Observability 1.11.2 for OpenShift
Network flows collector and monitoring solution.
AI Analysis
Technical Summary
The vulnerability CVE-2025-62718 affects Axios versions used in Red Hat Network Observability (NETOBSERV) 1.11.1 prior to 1.11.2. Axios does not correctly handle hostname normalization when processing NO_PROXY environment variable rules, enabling attackers to craft requests to loopback addresses (e.g., localhost or [::1]) that bypass NO_PROXY exclusions and are routed through the configured proxy. This behavior can be exploited to perform Server-Side Request Forgery (SSRF), allowing attackers to access internal or loopback services that should be protected. The impact is limited by the need for the attacker to control URLs in a server-side context, the presence of both HTTP_PROXY and NO_PROXY configurations, and the proxy's position or compromise to intercept traffic. Red Hat has classified this vulnerability as high severity but currently does not have an official fix that meets their deployment and stability criteria. The advisory references multiple CWEs related to input validation and security bypasses. Users are advised to monitor Red Hat advisories for updates.
Potential Impact
This vulnerability allows an attacker to bypass NO_PROXY settings in Axios, potentially enabling Server-Side Request Forgery (SSRF) attacks. SSRF can expose sensitive internal or loopback network services that are normally protected from external access. However, exploitation requires specific conditions: attacker control over URLs passed to Axios in a server-side environment, configured HTTP_PROXY and NO_PROXY environment variables, and a proxy capable of intercepting or rerouting traffic. The overall impact is high due to the confidentiality risk of accessing internal services, but the complexity and preconditions reduce the likelihood of exploitation.
Mitigation Recommendations
Red Hat currently does not provide an official fix that meets their criteria for this vulnerability. Mitigation options are limited or unavailable. Users should monitor Red Hat security advisories and apply updates when a suitable fix is released. Until then, restricting control over URLs passed to Axios in server-side contexts and carefully managing proxy configurations may reduce risk. Customers with Red Hat Technical Account Managers (TAM) can consult them for tailored guidance.
Red Hat Security Advisory: Network Observability 1.11.2 for OpenShift
Description
Network flows collector and monitoring solution.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2025-62718 affects Axios versions used in Red Hat Network Observability (NETOBSERV) 1.11.1 prior to 1.11.2. Axios does not correctly handle hostname normalization when processing NO_PROXY environment variable rules, enabling attackers to craft requests to loopback addresses (e.g., localhost or [::1]) that bypass NO_PROXY exclusions and are routed through the configured proxy. This behavior can be exploited to perform Server-Side Request Forgery (SSRF), allowing attackers to access internal or loopback services that should be protected. The impact is limited by the need for the attacker to control URLs in a server-side context, the presence of both HTTP_PROXY and NO_PROXY configurations, and the proxy's position or compromise to intercept traffic. Red Hat has classified this vulnerability as high severity but currently does not have an official fix that meets their deployment and stability criteria. The advisory references multiple CWEs related to input validation and security bypasses. Users are advised to monitor Red Hat advisories for updates.
Potential Impact
This vulnerability allows an attacker to bypass NO_PROXY settings in Axios, potentially enabling Server-Side Request Forgery (SSRF) attacks. SSRF can expose sensitive internal or loopback network services that are normally protected from external access. However, exploitation requires specific conditions: attacker control over URLs passed to Axios in a server-side environment, configured HTTP_PROXY and NO_PROXY environment variables, and a proxy capable of intercepting or rerouting traffic. The overall impact is high due to the confidentiality risk of accessing internal services, but the complexity and preconditions reduce the likelihood of exploitation.
Mitigation Recommendations
Red Hat currently does not provide an official fix that meets their criteria for this vulnerability. Mitigation options are limited or unavailable. Users should monitor Red Hat security advisories and apply updates when a suitable fix is released. Until then, restricting control over URLs passed to Axios in server-side contexts and carefully managing proxy configurations may reduce risk. Customers with Red Hat Technical Account Managers (TAM) can consult them for tailored guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:16874
- Cve Count
- 13
- Additional Cves
- ["CVE-2025-69873","CVE-2026-4800","CVE-2026-25679","CVE-2026-32280","CVE-2026-32282","CVE-2026-40175","CVE-2026-40895","CVE-2026-42033","CVE-2026-42035","CVE-2026-42039","CVE-2026-42041","CVE-2026-42043"]
Threat ID: 6a160974e29bf47b5063d582
Added to database: 05/26/2026, 20:58:28 UTC
Last enriched: 08/14/2026, 22:47:27 UTC
Last updated: 09/14/2026, 15:10:47 UTC
Views: 129
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.