Disclosure summary
## Summary Axios exposes `maxRedirects` to limit redirect following, and `maxRedirects: 0` is used by applications as a redirect-based SSRF guard. The Node HTTP adapter enforces this option. The fetch adapter does not read it and does not set a Fetch API `redirect` mode, so the runtime default of `redirect: 'follow'` applies. Applications are affected when they rely on `maxRedirects: 0` and use the fetch adapter, either explicitly or because the runtime selects it. ## Impact An attacker who controls the initial URL or a redirecting server can cause a fetch-adapter request to follow a redirect even though the caller configured `maxRedirects: 0`. If the redirect target is reachable only from the application environment, this can expose internal responses or trigger state-changing internal endpoints. This should not be described as unconditional SSRF. The bypass requires a redirect source, such as an attacker-controlled server or open redirect, and an application that trusted `maxRedirects: 0` as the redirect guard. ## Affected Functionality Affected: - `adapter: 'fetch'`. - Runtime environments where fetch is selected by adapter resolution. - Requests configured with `maxRedirects: 0
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-r4gj-5m52-g5wh
Open original source · Updated Sep 30, 2026
Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF
Source severity: HIGH / 7
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | axios | >= 1.17.0, < 1.20.0 | 1.20.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-30T11:31:58-04:00
MODIFIED 2026-09-30T11:32:00-04:00
INGESTED 2026-10-06T11:43:09-04:00