CVE-2026-101907 Axios 重定向策略绕过漏洞
影响可绕过重定向限制,访问内网资源或触发内部状态变更
Axios 是基于 Promise 的 HTTP 客户端,用于浏览器和 Node.js。在 1.17.0 至 1.20.0 之前的版本中,其 fetch 适配器在设置 maxRedirects: 0 时仍会跟随重定向,导致重定向策略被绕过。攻击者可借此访问内部响应或触达具有状态变更能力的内部端点。
影响范围
Axios 1.17.0 起至 1.20.0 之前的版本,且使用 fetch 适配器并设置 maxRedirects: 0 的场景。
漏洞详情
该漏洞属于安全策略绕过类问题。当请求使用 fetch 适配器并显式设置 maxRedirects 为 0(即禁止重定向)时,底层 fetch 实现仍会自动跟随服务端返回的重定向响应,而不是原样返回重定向结果。这样即使调用方明确禁用了重定向,请求仍会被转发到重定向目标地址,可能访问到本不应触达的内部响应或内部状态变更接口。
利用条件与风险
利用前提是应用使用受影响的 Axios 版本、采用 fetch 适配器并设置 maxRedirects: 0,同时请求目标存在可控或可预测的重定向。实战中可能导致 SSRF 类内网探测或内部接口被非预期调用,但需结合具体业务场景评估。
修复建议
官方已在 1.20.0 版本中修复,建议升级至 1.20.0 或更高版本。临时缓解措施包括避免使用 fetch 适配器处理不可信的重定向响应,或在应用层对重定向目标进行校验与限制。
Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter with maxRedirects set to zero and receives a redirect response. The underlying fetch implementation follows the redirect instead of returning the redirect response unchanged. The redirected request can access internal responses or reach state-changing internal endpoints despite redirects being disabled. This issue is fixed in version 1.20.0.