<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Axios (&gt;= 1.15.1, &lt; 1.20.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/axios--1.15.1--1.20.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 16:27:51 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/axios--1.15.1--1.20.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Axios Fetch Adapter Fails to Enforce Redirect Limits</title><link>https://feed.craftedsignal.io/briefs/2026-09-axios-ssrf-bypass/</link><pubDate>Wed, 30 Sep 2026 16:27:51 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-axios-ssrf-bypass/</guid><description>The Axios fetch adapter fails to enforce the maxRedirects: 0 configuration, enabling redirect-based SSRF by allowing requests to follow unexpected internal redirects.</description><content:encoded><![CDATA[<p>The Axios library provides a <code>maxRedirects</code> configuration option, frequently used by developers to mitigate redirect-based Server-Side Request Forgery (SSRF) by setting the limit to <code>0</code>. While the standard Node.js HTTP adapter correctly respects this constraint, the <code>fetch</code> adapter implemented in <code>lib/adapters/fetch.js</code> ignores this setting.</p>
<p>When applications rely on the <code>fetch</code> adapter, either through explicit configuration, environment-specific resolution (such as in Deno, Bun, or Cloudflare Workers), or automatic adapter selection, the library fails to pass a restrictive <code>redirect</code> mode to the underlying <code>fetch()</code> API. Consequently, the default runtime behavior of <code>redirect: 'follow'</code> takes precedence. This discrepancy allows attackers who can influence the initial request URL or provide a malicious redirecting server to bypass intended SSRF protections, leading to potential unauthorized access to internal resources or state-changing operations on internal endpoints reachable from the application environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for redirect-based SSRF, which may lead to the exposure of sensitive internal data or unauthorized modification of internal system states. The impact is significant for applications operating in cloud or serverless environments where network perimeter defenses are often bypassed by internal requests. If an internal service processes state-changing requests without additional authentication, an attacker can trigger unauthorized mutations by providing an open redirect or a malicious redirection chain that directs the application to the internal target.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Detection and remediation should focus on identifying applications using the fetch adapter in security-sensitive contexts.</p>
<ul>
<li>Audit application code for usages of <code>axios.get()</code> or <code>axios.request()</code> that specify <code>maxRedirects: 0</code> without explicit <code>fetchOptions</code> to define redirect behavior.</li>
<li>Where the fetch adapter is required, enforce manual redirect handling by setting <code>fetchOptions: { redirect: 'manual' }</code> in the axios configuration.</li>
<li>If the application environment supports it, prefer the Node.js HTTP adapter for requests requiring strict adherence to redirect limits.</li>
<li>Implement network-level egress filtering to prevent the application server from initiating connections to sensitive internal service segments (127.0.0.1, 169.254.169.254, or private RFC1918 ranges) unless explicitly required.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>prototype-pollution</category><category>javascript</category><category>nodejs</category><category>supply-chain</category><category>ssrf</category><category>library-vulnerability</category></item></channel></rss>