Skip to content
Threat Feed
high advisory

Axios Fetch Adapter Fails to Enforce Redirect Limits

The Axios fetch adapter fails to enforce the maxRedirects: 0 configuration, enabling redirect-based SSRF by allowing requests to follow unexpected internal redirects.

What's new

  • 1. added coverage for Axios (>= 1.13.0, < 1.20.0) Sep 30, 16:28 via ghsa
  • 2. added coverage for axios (>= 0.28.0, < 0.34.0) +1 products Sep 30, 16:28 via ghsa

The Axios library provides a maxRedirects configuration option, frequently used by developers to mitigate redirect-based Server-Side Request Forgery (SSRF) by setting the limit to 0. While the standard Node.js HTTP adapter correctly respects this constraint, the fetch adapter implemented in lib/adapters/fetch.js ignores this setting.

When applications rely on the fetch adapter, either through explicit configuration, environment-specific resolution (such as in Deno, Bun, or Cloudflare Workers), or automatic adapter selection, the library fails to pass a restrictive redirect mode to the underlying fetch() API. Consequently, the default runtime behavior of redirect: 'follow' takes precedence. This discrepancy allows attackers who can influence the initial request URL or provide a malicious redirecting server to bypass intended SSRF protections, leading to potential unauthorized access to internal resources or state-changing operations on internal endpoints reachable from the application environment.

Impact

Successful exploitation allows for redirect-based SSRF, which may lead to the exposure of sensitive internal data or unauthorized modification of internal system states. The impact is significant for applications operating in cloud or serverless environments where network perimeter defenses are often bypassed by internal requests. If an internal service processes state-changing requests without additional authentication, an attacker can trigger unauthorized mutations by providing an open redirect or a malicious redirection chain that directs the application to the internal target.

Recommendation

Detection and remediation should focus on identifying applications using the fetch adapter in security-sensitive contexts.

  • Audit application code for usages of axios.get() or axios.request() that specify maxRedirects: 0 without explicit fetchOptions to define redirect behavior.
  • Where the fetch adapter is required, enforce manual redirect handling by setting fetchOptions: { redirect: 'manual' } in the axios configuration.
  • If the application environment supports it, prefer the Node.js HTTP adapter for requests requiring strict adherence to redirect limits.
  • Implement network-level egress filtering to prevent the application server from initiating connections to sensitive internal service segments (127.0.0.1, 169.254.169.254, or private RFC1918 ranges) unless explicitly required.

Immediate actions

Audit codebases using Axios to identify instances where maxRedirects: 0 is used with the fetch adapter

Development 72h

Mitigations

Update axios to version 1.18.1 or later

immediate Development

SSRF via fetch adapter redirect bypass