PT-2026-99950 · Npm · Axios

·

CVE-2026-101907

·

Published

2026-09-28

·

Updated

2026-09-30

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Axios versions 1.17.0 through 1.19.x
Description The fetch adapter bypasses the maxRedirects: 0 redirect policy. When a request is configured with maxRedirects set to zero and receives a redirect response, the underlying fetch implementation follows the redirect instead of returning the response unchanged. This behavior allows redirected requests to access internal responses or reach state-changing internal endpoints even when redirects are disabled.
Recommendations Update to version 1.20.0.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101907
GHSA-R4GJ-5M52-G5WH

Affected Products

Axios