Repository navigation
chore(deps): update dependency axios to v1.20.0 [security] - #1067
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #1067 +/- ##
==========================================
- Coverage 76.12% 76.09% -0.03%
==========================================
Files 67 67
Lines 3619 3619
==========================================
- Hits 2755 2754 -1
- Misses 653 654 +1
Partials 211 211 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.18.1→1.20.0Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF
CVE-2026-101907 / GHSA-r4gj-5m52-g5wh
More information
Details
Summary
Axios exposes
maxRedirectsto limit redirect following, andmaxRedirects: 0is used by applications as a redirect-based SSRF guard. The Node HTTP adapter enforces this option. The fetch adapter does not read it and does not set a Fetch APIredirectmode, so the runtime default ofredirect: 'follow'applies.Applications are affected when they rely on
maxRedirects: 0and use the fetch adapter, either explicitly or because the runtime selects it.Impact
An attacker who controls the initial URL or a redirecting server can cause a fetch-adapter request to follow a redirect even though the caller configured
maxRedirects: 0. If the redirect target is reachable only from the application environment, this can expose internal responses or trigger state-changing internal endpoints.This should not be described as unconditional SSRF. The bypass requires a redirect source, such as an attacker-controlled server or open redirect, and an application that trusted
maxRedirects: 0as the redirect guard.Affected Functionality
Affected:
adapter: 'fetch'.maxRedirects: 0but withoutfetchOptions.redirect: 'manual'or equivalent runtime-specific redirect control.Not affected:
maxRedirects: 0.Technical Details
lib/adapters/fetch.jsdestructures many fields fromresolveConfig(config), but notmaxRedirects. It then builds fetch options without aredirectkey:Because
redirectis absent, the Fetch API default is to follow redirects.Local verification on axios
1.18.1showed the HTTP adapter throwing withmaxRedirects: 0, while the fetch adapter followed the same loopback302and returned the internal response.Proof of Concept of Attack
Constrained local demonstration:
302 Location: http://127.0.0.1:<server-b>/internal.INTERNAL.Workarounds
For fetch-adapter requests, set
fetchOptions: { redirect: 'manual' }where the runtime supports it, or use the Node HTTP adapter for requests that rely on axios redirect limits.Original report
Summary
Axios 1.17.0 exposes
maxRedirectsas a configuration option to limit redirect following, and setting it to0is a documented pattern for preventing redirect-based SSRF. The HTTP adapter enforces this viafollow-redirects. The fetch adapter does not readmaxRedirectsat all - it passes requests to the underlyingfetch()call with noredirectoption, which defaults to'follow', so redirects are followed by the runtime rather than being constrained by axiosmaxRedirects.In the attached PoC, a request issued with
maxRedirects: 0andadapter: 'fetch'follows a302redirect to an internal service and returns its response, while the same request withadapter: 'http'correctly throws. A second bypass case demonstrates that the redirect can reach a state-changing internal endpoint, not just read-only ones, proving both confidentiality and integrity impact.This affects any application that sets
maxRedirects: 0as a redirect guard and runs in an environment where the fetch adapter is active: Deno, Bun, Cloudflare Workers, or Node.js withadapter: 'fetch'set explicitly.Details
The fetch adapter destructures config fields from
resolveConfigatlib/adapters/fetch.js:The options object passed to
fetch()has noredirectkey:Because no
redirectkey is present, the Fetch API default ofredirect: 'follow'applies, so redirects are handled by the runtime rather than constrained by axiosmaxRedirects. The HTTP adapter, by contrast, delegates tofollow-redirects, which readsmaxRedirects, enforces the cap, and stripsAuthorization,Cookie, andProxy-Authorizationon cross-origin redirects.The discrepancy between adapters is not documented. The threat model covers credential stripping on redirects (T-R2) and cites
follow-redirectsas the mitigation, but makes no mention that the fetch adapter does not participate in this mitigation. See: https://github.com/axios/axios/blob/master/THREATMODEL.md#t-r2-credential-leakage-on-cross-origin-redirectThe behaviour difference between adapters is summarised below:
config.maxRedirectsmaxRedirects: 0Authorizationcross-originfollow-redirects>=1.15.8)Cookiecross-originWhen is the fetch adapter selected?
httpmodule available; the adapter list falls through to'fetch'axios.get(url, { adapter: 'fetch' })axios.create({ adapter: ['fetch'] })PoC
Run:
Observed:
Control
Axios does correctly enforce
maxRedirects: 0in the HTTP adapter. The[CONTROL]case above confirms this: the same request withadapter: 'http'throws rather than following the redirect, and the internal hit counter stays at0:The issue is not that
maxRedirectsis broken globally. It is enforced correctly for the HTTP adapter. The bypass is specific to the fetch adapter, which never reads the option and passes noredirectconstraint to the underlyingfetch()call.Impact
This is a redirect enforcement bypass affecting axios applications running in environments where the fetch adapter is active.
The internal admin route in the PoC simulates an affected deployment where a redirected request can reach state-changing internal APIs. The vulnerability is that
maxRedirects: 0is silently ignored by the fetch adapter; the exact impact depends on what redirect targets are reachable from the runtime.The impact is environment- and configuration-dependent. It affects axios users who:
maxRedirects: 0as a defense against redirect-based SSRF, andIn these cases, a
302redirect from the initial target is followed silently by default, unless the caller separately setsfetchOptions.redirect. If the redirect target is an internal service, the application returns its response to the caller with no indication that a redirect occurred or thatmaxRedirectswas not honoured. The failure is silent: no error is thrown, no warning is logged.The bypass is not limited to read-only access. As demonstrated by the second bypass case, a redirect to a state-changing internal endpoint succeeds equally. An attacker who can influence the redirect destination, for example through an open redirect on the initial target or a server they control, can reach internal and trigger mutations that the application never intended to issue.
Potentially affected environments include:
httpmodule.adapter: 'fetch'or a custom adapter list that resolves to fetch.maxRedirects: 0and runs across multiple environments with different adapter selection.Internal services reachable via a redirect include cloud instance metadata endpoints (
169.254.169.254), unauthenticated local services such as Redis or internal admin APIs, and other hosts accessible from the application's network that are not intended to be reachable by the caller. The hit counter in the PoC makes the access concrete:0after the HTTP control,1after the confidentiality bypass,2after the integrity bypass.This should not be characterised as an unconditional SSRF. The bypass requires either an open redirect on the initial target, or a URL that is itself a redirect. The issue is that
maxRedirects: 0, which is the intended mitigation for this class of attack, is silently non-functional in the fetch adapter, leaving applications with a false sense of protection.Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
axios/axios (axios)
v1.20.0Compare Source
v1.20.0 — August 19, 2026
This release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.
🔒 Security Fixes
🐛 Bug Fixes
🔧 Maintenance & Chores
🌟 New Contributors
We are thrilled to welcome our new contributors. Thank you for helping improve axios:
Full Changelog (axios/axios@v1.19.0...v1.20.0)
v1.19.0Compare Source
This release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.