Axios Fetch Adapter Fails to Enforce Redirect Limits
The Axios fetch adapter fails to enforce the maxRedirects: 0 configuration, enabling redirect-based SSRF by allowing requests to follow unexpected internal redirects.
What's new
The Axios library provides a maxRedirects configuration option, frequently used by developers to mitigate redirect-based Server-Side Request Forgery (SSRF) by setting the limit to 0. While the standard Node.js HTTP adapter correctly respects this constraint, the fetch adapter implemented in lib/adapters/fetch.js ignores this setting.
When applications rely on the fetch adapter, either through explicit configuration, environment-specific resolution (such as in Deno, Bun, or Cloudflare Workers), or automatic adapter selection, the library fails to pass a restrictive redirect mode to the underlying fetch() API. Consequently, the default runtime behavior of redirect: 'follow' takes precedence. This discrepancy allows attackers who can influence the initial request URL or provide a malicious redirecting server to bypass intended SSRF protections, leading to potential unauthorized access to internal resources or state-changing operations on internal endpoints reachable from the application environment.
Impact
Successful exploitation allows for redirect-based SSRF, which may lead to the exposure of sensitive internal data or unauthorized modification of internal system states. The impact is significant for applications operating in cloud or serverless environments where network perimeter defenses are often bypassed by internal requests. If an internal service processes state-changing requests without additional authentication, an attacker can trigger unauthorized mutations by providing an open redirect or a malicious redirection chain that directs the application to the internal target.
Recommendation
Detection and remediation should focus on identifying applications using the fetch adapter in security-sensitive contexts.
- Audit application code for usages of
axios.get()oraxios.request()that specifymaxRedirects: 0without explicitfetchOptionsto define redirect behavior. - Where the fetch adapter is required, enforce manual redirect handling by setting
fetchOptions: { redirect: 'manual' }in the axios configuration. - If the application environment supports it, prefer the Node.js HTTP adapter for requests requiring strict adherence to redirect limits.
- Implement network-level egress filtering to prevent the application server from initiating connections to sensitive internal service segments (127.0.0.1, 169.254.169.254, or private RFC1918 ranges) unless explicitly required.
Immediate actions
Audit codebases using Axios to identify instances where maxRedirects: 0 is used with the fetch adapter
Mitigations
Update axios to version 1.18.1 or later
SSRF via fetch adapter redirect bypass