CVE-2026-101907High· 7.0▾ MidnightPoC availableAxios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter with maxRedirects set to zero and receive…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 38.5 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter with maxRedirects set to zero and receives a redirect response. The underlying fetch implementation follows the redirect instead of returning the redirect response unchanged. The redirected request can access internal responses or reach state-changing internal endpoints despite redirects being disabled. This issue is fixed in version 1.20.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-101905High· 7.6Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101908Medium· 6.9Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101903High· 8.2Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101904Medium· 6.9Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101900Medium· 6.9Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101898High· 7.0Axios is a promise-based HTTP client for the browser and Node.js