OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-101907

HIGH · CVSS 7 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Axios versions 1.17.0 to 1.20.0 are vulnerable due to a flaw in the fetch adapter that allows it to bypass the maxRedirects: 0 policy, leading to unintended redirection of requests. This can result in unauthorized access to internal responses or state-changing endpoints, posing a significant security risk. Developers and organizations using affected versions of Axios should prioritize upgrading to version 1.20.0 or later to mitigate this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-101907
Severity
HIGH
CVSS
7
EPSS
0.41%

Original NVD Description

Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter with maxRedirects set to zero and receives a redirect response. The underlying fetch implementation follows the redirect instead of returning the redirect response unchanged. The redirected request can access internal responses or reach state-changing internal endpoints despite redirects being disabled. This issue is fixed in version 1.20.0.