AI analysis
In Axios 1.17.0 through versions before 1.20.0, the fetch adapter ignores a maxRedirects: 0 policy and lets the underlying fetch implementation follow redirects. An application that expected the redirect response to be returned unchanged can instead have the follow-up request reach internal responses or state-changing internal endpoints. Impact is on the systems reached after the redirect (high subsequent confidentiality and integrity in the CVSS 4.0 score), not on Axios itself; the issue is tracked as CWE-441 and CWE-601. Browser and Node.js consumers of those Axios versions that use the fetch adapter with redirects disabled are affected. No public proof-of-concept is known, the flaw is not in CISA KEV, and it is fixed in Axios 1.20.0.
What to do: Upgrade Axios to 1.20.0 or later in every application that uses the fetch adapter. Until that is deployed, do not rely on maxRedirects: 0 to stop redirects, and review server-side Axios calls to user-influenced URLs for possible access to internal or state-changing endpoints. Confirm the resolved version in lockfiles, not only the range declared in package.json.
Affected
| axios | 1.17.0 up to, but not including, 1.20.0 |
Estimated exposure
largeon the order of 100,000–1,000,000 applications on Axios 1.17.0–<1.20.0 (exploitable subset smaller) — Axios is one of the most widely used JavaScript HTTP clients, with tens of millions of weekly npm downloads and a very large downstream dependency base; only the narrow 1.17.0–<1.20.0 range is affected, and practical exposure further…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter with maxRedirects set to zero and receives a redirect response. The underlying fetch implementation follows the redirect instead of returning the redirect response unchanged. The redirected request can access internal responses or reach state-changing internal endpoints despite redirects being disabled. This issue is fixed in version 1.20.0.