CVE-2026-42040 - Vulnerability Analysis
LowCVSS: 3.7Last Updated: April 27, 2026
Axios - Insecure Encoding
Published: April 24, 2026Updated: April 27, 2026PoC AvailableRemote Exploitable
Overview
Axios prior to 1.15.1 and 0.31.1 contains an insecure encoding vulnerability caused by charMap reversing safe percent-encoding of null bytes in AxiosURLSearchParams.js, letting attackers inject raw null bytes, exploit requires crafted requests.
Severity & Score
Severity: Low
CVSS Score: 3.7
Impact
Attackers can inject raw null bytes, potentially leading to unexpected behavior or security issues in applications using Axios.
Mitigation
Update to version 1.15.1 or 0.31.1 or later.
Related Resources
Details
- CVE ID
- CVE-2026-42040
- Severity
- Low
- CVSS Score
- 3.7
- Type
- undefined
- Status
- confirmed
CWE
- CWE-116
CVSS Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N