LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-42040

CVE-2026-42040 - Vulnerability Analysis

LowCVSS: 3.7

Last Updated: April 27, 2026

Axios - Insecure Encoding

Published: April 24, 2026Updated: April 27, 2026PoC AvailableRemote Exploitable

Overview

Axios prior to 1.15.1 and 0.31.1 contains an insecure encoding vulnerability caused by charMap reversing safe percent-encoding of null bytes in AxiosURLSearchParams.js, letting attackers inject raw null bytes, exploit requires crafted requests.

Severity & Score

Severity: Low
CVSS Score: 3.7

Impact

Attackers can inject raw null bytes, potentially leading to unexpected behavior or security issues in applications using Axios.

Mitigation

Update to version 1.15.1 or 0.31.1 or later.

Details

CVE ID
CVE-2026-42040
Severity
Low
CVSS Score
3.7
Type
undefined
Status
confirmed

CWE

  • CWE-116

CVSS Metrics

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N