Vulnerability Description
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the encode() function in lib/helpers/AxiosURLSearchParams.js contains a character mapping (charMap) at line 21 that reverses the safe percent-encoding of null bytes. After encodeURIComponent('\x00') correctly produces the safe sequence %00, the charMap entry '%00': '\x00' converts it back to a raw null byte. Primary impact is limited because the standard axios request flow is not affected. This vulnerability is fixed in 1.15.1 and 0.31.1.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Axios | Axios | < 0.31.1 |
Related Weaknesses (CWE)
References
- https://github.com/axios/axios/security/advisories/GHSA-xhjh-pmcv-23jwExploitMitigationVendor Advisory
- https://github.com/axios/axios/security/advisories/GHSA-xhjh-pmcv-23jwExploitMitigationVendor Advisory
FAQ
What is CVE-2026-42040?
CVE-2026-42040 is a vulnerability with a CVSS score of 3.7 (LOW). Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the encode() function in lib/helpers/AxiosURLSearchParams.js contains a character mapping (charMap) at lin...
How severe is CVE-2026-42040?
CVE-2026-42040 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-42040?
Check the references section above for vendor advisories and patch information. Affected products include: Axios Axios.