AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-101907.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 7CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 30, 2026

Disclosure summary

## Summary Axios exposes `maxRedirects` to limit redirect following, and `maxRedirects: 0` is used by applications as a redirect-based SSRF guard. The Node HTTP adapter enforces this option. The fetch adapter does not read it and does not set a Fetch API `redirect` mode, so the runtime default of `redirect: 'follow'` applies. Applications are affected when they rely on `maxRedirects: 0` and use the fetch adapter, either explicitly or because the runtime selects it. ## Impact An attacker who controls the initial URL or a redirecting server can cause a fetch-adapter request to follow a redirect even though the caller configured `maxRedirects: 0`. If the redirect target is reachable only from the application environment, this can expose internal responses or trigger state-changing internal endpoints. This should not be described as unconditional SSRF. The bypass requires a redirect source, such as an attacker-controlled server or open redirect, and an application that trusted `maxRedirects: 0` as the redirect guard. ## Affected Functionality Affected: - `adapter: 'fetch'`. - Runtime environments where fetch is selected by adapter resolution. - Requests configured with `maxRedirects: 0

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-r4gj-5m52-g5wh

Open original source · Updated Sep 30, 2026

Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF

Source severity: HIGH / 7

EcosystemPackageAffected rangeFirst patched
npmaxios>= 1.17.0, < 1.20.01.20.0

Original records & references

PUBLISHED 2026-09-30T11:31:58-04:00
MODIFIED 2026-09-30T11:32:00-04:00
INGESTED 2026-10-06T11:43:09-04:00