axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.
No PoCs from references.
- https://github.com/DripEmail/drip-nodejs
- https://github.com/squidx232/loadtest
- https://github.com/tdonaworth/axios-ssrf