Npm · Axios · CVE-2026-101907
**Name of the Vulnerable Software and Affected Versions**
Axios versions 1.17.0 through 1.19.x
**Description**
The fetch adapter bypasses the `maxRedirects: 0` redirect policy. When a request is configured with `maxRedirects` set to zero and receives a redirect response, the underlying fetch implementation follows the redirect instead of returning the response unchanged. This behavior allows redirected requests to access internal responses or reach state-changing internal endpoints even when redirects are disabled.
**Recommendations**
Update to version 1.20.0.