Looking for the vulnerability index of Invicti's legacy products?
axios : Unintended Proxy or Intermediary ('Confused Deputy') Vulnerability (CVE-2026-101907) - Vulnerability Database

axios : Unintended Proxy or Intermediary ('Confused Deputy') Vulnerability (CVE-2026-101907)

Description

Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter with maxRedirects set to zero and receives a redirect response. The underlying fetch implementation follows the redirect instead of returning the redirect response unchanged. The redirected request can access internal responses or reach state-changing internal endpoints despite redirects being disabled.

Related Vulnerabilities