CVE-2026-101907
Received Received - Intake

Axios Fetch Adapter Redirect Policy Bypass

Vulnerability report for CVE-2026-101907, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter with maxRedirects set to zero and receives a redirect response. The underlying fetch implementation follows the redirect instead of returning the redirect response unchanged. The redirected request can access internal responses or reach state-changing internal endpoints despite redirects being disabled. This issue is fixed in version 1.20.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
axios axios to 1.20.0 (inc)
axios axios From 1.17.0 (inc) to 1.20.0 (inc)
axios axios 1.20.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
CWE-441 The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101907 is a vulnerability in the Axios library where the fetch adapter does not respect the maxRedirects: 0 setting. This setting is meant to block redirects to prevent SSRF attacks, but the fetch adapter ignores it and follows redirects anyway. As a result, requests using the fetch adapter can access internal services or endpoints that should be unreachable, potentially exposing sensitive data or triggering unauthorized actions.

Detection Guidance

To detect this vulnerability, check if your application uses the Axios fetch adapter with maxRedirects: 0. Inspect network logs for unexpected redirects or internal endpoint access. No specific commands are provided in the context.

Impact Analysis

This vulnerability allows an attacker to force your application to access internal services or endpoints by manipulating redirects. If your application uses the fetch adapter with maxRedirects: 0, the attacker could bypass this security measure and access sensitive internal responses or trigger state-changing actions on internal endpoints, leading to confidentiality or integrity breaches.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR (data protection) or HIPAA (healthcare data privacy). Exposure of internal responses or unauthorized state changes could result in data breaches, triggering regulatory penalties or legal consequences.

Mitigation Strategies

Upgrade Axios to version 1.20.0 or later. If using the fetch adapter, set fetchOptions: { redirect: 'manual' } to enforce manual redirect handling. Alternatively, switch to the Node HTTP adapter for requests requiring redirect limits.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101907. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart