Skip to main content
Vulnerability Database/CVE-2025-69202

CVE-2025-69202: Axios Cache Interceptor Auth Bypass Flaw

CVE-2025-69202 is an authorization bypass vulnerability in Axios Cache Interceptor that causes incorrect cached responses when using different auth tokens. This post covers the technical details, affected versions, impact on server-side applications, and mitigation steps.

Published:

CVE-2025-69202 Overview

CVE-2025-69202 is an authorization bypass vulnerability in axios-cache-interceptor, a caching layer for the axios HTTP client. Versions prior to 1.11.1 generate cache keys using only the request URL. The library ignores the Authorization header and disregards upstream Vary: Authorization response directives. Server-side applications that proxy requests from multiple authenticated users to upstream services return cached responses belonging to other users. The flaw enables cross-session data leakage and bypasses authorization checks at the caching layer. This weakness maps to [CWE-524] (Use of Cache Containing Sensitive Information) and [CWE-639] (Authorization Bypass Through User-Controlled Key).

Critical Impact

Server-side services using axios-cache-interceptor to relay authenticated requests may serve one user's cached response to another, leaking sensitive data and bypassing upstream authorization.

Affected Products

  • axios-cache-interceptor versions prior to 1.11.1
  • Node.js server-side applications (APIs, proxies, backend services) using the library to cache upstream calls
  • Multi-tenant backends where upstream services rely on Vary: Authorization to differentiate cached responses

Discovery Timeline

  • 2025-12-29 - CVE-2025-69202 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-69202

Vulnerability Analysis

The vulnerability resides in the cache key derivation logic of axios-cache-interceptor. The library generates cache keys from the request URL and method alone. Request headers, including Authorization, are excluded from the key. When an upstream service returns Vary: Authorization, HTTP semantics require caches to include the Authorization header value in the cache key. The library ignores this directive.

Browser or single-user client contexts are unaffected because each session maintains an isolated cache. Server-side deployments that fan out requests from many authenticated users to a shared upstream cache are the exposed surface. A response fetched using User A's token is returned to User B if User B's request targets the same URL before the entry expires.

Root Cause

The root cause is missing Vary header processing and header-insensitive key generation. The library did not honor cache-control semantics defined in RFC 7234 for authorization-varying responses. Key collisions between distinct principals violate the isolation guarantee expected by upstream services.

Attack Vector

Exploitation requires network access to a vulnerable server-side application and low-privilege authenticated credentials. An attacker with valid credentials issues a request to an endpoint recently accessed by a higher-privileged user. The library returns the cached response for the previously issued request without re-validating the current user's authorization scope.

typescript
// Patch excerpt: src/cache/axios.ts
   AxiosInstance,
   AxiosInterceptorManager,
   AxiosRequestConfig,
+  AxiosRequestHeaders,
   AxiosResponse,
-  AxiosResponseHeaders,
   InternalAxiosRequestConfig
 } from 'axios';
 import type { CacheInstance, CacheProperties } from './cache.js';

// Patch excerpt: src/header/extract.ts
+import type { AxiosRequestHeaders, AxiosResponseHeaders } from 'axios';
+
/**
 * Extracts specified header values from request headers.
 * Generic utility for extracting a subset of headers.
 */

Source: GitHub commit 49a8080. The patch normalizes request header casing and enables Vary header processing so that authorization values participate in cache key generation.

Detection Methods for CVE-2025-69202

Indicators of Compromise

  • Application logs showing users receiving HTTP responses containing another user's identifiers, session data, or profile fields
  • Upstream service audit logs with fewer authenticated requests than the front-end proxy issued, indicating cache hits that bypass token validation
  • Presence of axios-cache-interceptor versions below 1.11.1 in package.json or package-lock.json

Detection Strategies

  • Perform software composition analysis (SCA) across Node.js repositories and container images to enumerate vulnerable versions of axios-cache-interceptor
  • Add integration tests that issue two requests with different Authorization headers to the same URL and assert distinct response bodies
  • Review upstream API responses for the Vary: Authorization header and confirm the caching layer honors it

Monitoring Recommendations

  • Alert on user-attributable data appearing in responses served to sessions with mismatched user IDs or tenants
  • Track anomalous ratios of upstream requests to inbound authenticated requests, which may indicate cache-key collisions
  • Log the resolved cache key alongside the request principal to detect keys shared across identities

How to Mitigate CVE-2025-69202

Immediate Actions Required

  • Upgrade axios-cache-interceptor to version 1.11.1 or later in all affected server-side services
  • Invalidate existing cache stores after upgrading so responses cached under the vulnerable key scheme are evicted
  • Audit multi-tenant backends that proxy authenticated calls through the library and confirm upstream Vary semantics are respected

Patch Information

The fix landed in the GitHub commit 49a8080 and is described in the GitHub Security Advisory GHSA-x4m5-4cw8-vc44. Version 1.11.1 enables automatic Vary header support by default, so cache keys include the Authorization value when upstream responses declare Vary: Authorization.

Workarounds

  • Disable caching for endpoints that return per-user data until the library is upgraded
  • Provide a custom generateKey function that incorporates the request Authorization header or an authenticated principal identifier
  • Segment cache instances per tenant or user so cached responses cannot cross authorization boundaries
bash
# Upgrade to the patched release
npm install axios-cache-interceptor@^1.11.1

# Verify the resolved version
npm ls axios-cache-interceptor

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.