天下漏洞,尽知其名
MEDIUM

CVE-2026-101907 Axios 重定向策略绕过漏洞

影响可绕过重定向限制,访问内网资源或触发内部状态变更

MEDIUM
暂无 CVSS 评分
AI 研判

Axios 是基于 Promise 的 HTTP 客户端,用于浏览器和 Node.js。在 1.17.0 至 1.20.0 之前的版本中,其 fetch 适配器在设置 maxRedirects: 0 时仍会跟随重定向,导致重定向策略被绕过。攻击者可借此访问内部响应或触达具有状态变更能力的内部端点。

影响范围

Axios

Axios 1.17.0 起至 1.20.0 之前的版本,且使用 fetch 适配器并设置 maxRedirects: 0 的场景。

漏洞详情

该漏洞属于安全策略绕过类问题。当请求使用 fetch 适配器并显式设置 maxRedirects 为 0(即禁止重定向)时,底层 fetch 实现仍会自动跟随服务端返回的重定向响应,而不是原样返回重定向结果。这样即使调用方明确禁用了重定向,请求仍会被转发到重定向目标地址,可能访问到本不应触达的内部响应或内部状态变更接口。

利用条件与风险

利用前提是应用使用受影响的 Axios 版本、采用 fetch 适配器并设置 maxRedirects: 0,同时请求目标存在可控或可预测的重定向。实战中可能导致 SSRF 类内网探测或内部接口被非预期调用,但需结合具体业务场景评估。

修复建议

官方已在 1.20.0 版本中修复,建议升级至 1.20.0 或更高版本。临时缓解措施包括避免使用 fetch 适配器处理不可信的重定向响应,或在应用层对重定向目标进行校验与限制。

原始情报

Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter with maxRedirects set to zero and receives a redirect response. The underlying fetch implementation follows the redirect instead of returning the redirect response unchanged. The redirected request can access internal responses or reach state-changing internal endpoints despite redirects being disabled. This issue is fixed in version 1.20.0.