CVE-2026-101907
Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter with maxRedirects set to zero and receives a redirect response. The underlying fetch implementation follows the redirect instead of returning the redirect response unchanged. The redirected request can access internal responses or reach state-changing internal endpoints despite redirects being disabled. This issue is fixed in version 1.20.0.
| CWE | CWE-441 CWE-601 |
| Vendor | axios |
| Product | axios |
| Published | Sep 28, 2026 |
| Last Updated | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for axios axios
Be the first to know when new unknown vulnerabilities affecting axios axios are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
axios / axios
>= 1.17.0, < 1.20.0