Skip to content

NO_PROXY=example.com does not bypass subdomains for http.request(), unlike fetch() #65616

Description

@dibenkobit

Version

v24.18.1, also on main (v27.0.0-pre)

Platform

Darwin xxx.local 25.3.0 Darwin Kernel Version 25.3.0: Wed Jan 28 20:54:46 PST 2026; root:xnu-12377.91.3~2/RELEASE_ARM64_T6000 arm64

Subsystem

http

What steps will reproduce the bug?

Dead proxy on port 1 — the error code shows where the request went:

NODE_USE_ENV_PROXY=1 HTTP_PROXY=http://127.0.0.1:1 NO_PROXY=example.com node repro.js
const http = require('node:http');

http.get('http://internal.example.com/').on('error', (e) => console.log(e.cause?.code ?? e.code));
// ECONNREFUSED — went through the proxy

fetch('http://internal.example.com/').catch((e) => console.log(e.cause?.code ?? e.code));
// ENOTFOUND — bypassed, hit DNS

How often does it reproduce? Is there a required condition?

Always, when the NO_PROXY entry has no leading dot and the request host is a subdomain of that entry.

What is the expected behavior? Why is that the expected behavior?

Same NO_PROXY in the same process should mean the same thing for http.request() / http.get() and fetch(). http.setGlobalProxyFromEnv() and the docs present one NO_PROXY format for both.

fetch() (undici EnvHttpProxyAgent) already treats a plain example.com as the host and its subdomains, with a label boundary so notexample.com does not match. http should do the same.

What do you see instead?

ProxyConfig#shouldUseProxy exact-matches a plain entry against the hostname. NO_PROXY=example.com therefore does not bypass internal.example.com for http.request(), while fetch() does.

The docs currently describe this as “Exact host name match”, which matches the http implementation and not fetch().

Additional information

Refs: #57872, #62907

Activity

  1. inoway46 commented on Aug 30, 2026

    @inoway46
    Contributor

    Thanks for reporting. I reproduced the sample code locally on main at 045ff95, and this looks valid to me.

    The behavior in fetch() was changed in nodejs/undici#4676, and #57872 includes the following item:

    Share code between the fetch and the http(s) builtin implementation (e.g. env var parsing & matching)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions