axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.
{ "versions": [ { "introduced": "1.3.2" }, { "fixed": "1.7.4" } ] }
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-39338.json"