{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/axios--0.28.0--0.34.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["axios (\u003c 1.18.1)","axios (\u003e= 0.28.0, \u003c 0.34.0)","axios (\u003e= 1.15.1, \u003c 1.20.0)","Axios (\u003e= 1.13.0, \u003c 1.20.0)"],"_cs_severities":["high"],"_cs_tags":["prototype-pollution","javascript","nodejs","supply-chain","ssrf","library-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Axios"],"content_html":"\u003cp\u003eThe Axios library provides a \u003ccode\u003emaxRedirects\u003c/code\u003e configuration option, frequently used by developers to mitigate redirect-based Server-Side Request Forgery (SSRF) by setting the limit to \u003ccode\u003e0\u003c/code\u003e. While the standard Node.js HTTP adapter correctly respects this constraint, the \u003ccode\u003efetch\u003c/code\u003e adapter implemented in \u003ccode\u003elib/adapters/fetch.js\u003c/code\u003e ignores this setting.\u003c/p\u003e\n\u003cp\u003eWhen applications rely on the \u003ccode\u003efetch\u003c/code\u003e adapter, either through explicit configuration, environment-specific resolution (such as in Deno, Bun, or Cloudflare Workers), or automatic adapter selection, the library fails to pass a restrictive \u003ccode\u003eredirect\u003c/code\u003e mode to the underlying \u003ccode\u003efetch()\u003c/code\u003e API. Consequently, the default runtime behavior of \u003ccode\u003eredirect: 'follow'\u003c/code\u003e takes precedence. This discrepancy allows attackers who can influence the initial request URL or provide a malicious redirecting server to bypass intended SSRF protections, leading to potential unauthorized access to internal resources or state-changing operations on internal endpoints reachable from the application environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for redirect-based SSRF, which may lead to the exposure of sensitive internal data or unauthorized modification of internal system states. The impact is significant for applications operating in cloud or serverless environments where network perimeter defenses are often bypassed by internal requests. If an internal service processes state-changing requests without additional authentication, an attacker can trigger unauthorized mutations by providing an open redirect or a malicious redirection chain that directs the application to the internal target.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection and remediation should focus on identifying applications using the fetch adapter in security-sensitive contexts.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit application code for usages of \u003ccode\u003eaxios.get()\u003c/code\u003e or \u003ccode\u003eaxios.request()\u003c/code\u003e that specify \u003ccode\u003emaxRedirects: 0\u003c/code\u003e without explicit \u003ccode\u003efetchOptions\u003c/code\u003e to define redirect behavior.\u003c/li\u003e\n\u003cli\u003eWhere the fetch adapter is required, enforce manual redirect handling by setting \u003ccode\u003efetchOptions: { redirect: 'manual' }\u003c/code\u003e in the axios configuration.\u003c/li\u003e\n\u003cli\u003eIf the application environment supports it, prefer the Node.js HTTP adapter for requests requiring strict adherence to redirect limits.\u003c/li\u003e\n\u003cli\u003eImplement network-level egress filtering to prevent the application server from initiating connections to sensitive internal service segments (127.0.0.1, 169.254.169.254, or private RFC1918 ranges) unless explicitly required.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T16:28:09Z","date_published":"2026-09-30T16:27:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-axios-ssrf-bypass/","summary":"The Axios fetch adapter fails to enforce the maxRedirects: 0 configuration, enabling redirect-based SSRF by allowing requests to follow unexpected internal redirects.","title":"Axios Fetch Adapter Fails to Enforce Redirect Limits","url":"https://feed.craftedsignal.io/briefs/2026-09-axios-ssrf-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Axios (\u003e= 0.28.0, \u003c 0.34.0)","version":"https://jsonfeed.org/version/1.1"}