Executive brief
Axios is a popular HTTP client library used by developers to make web requests. A defect in the URL parameter encoding function can allow null bytes to be injected into HTTP request URLs in certain usage patterns. While the standard Axios request flow is not affected, applications that use the library's internal parameter serializer directly or with custom encoders could produce malformed URLs that may be misinterpreted by downstream services, potentially leading to URL truncation, WAF bypass, or log injection.
Technical details
The vulnerability is a reverse-encoding defect in the encode() function within lib/helpers/AxiosURLSearchParams.js. The charMap at line 21 contains an entry '%00': '\x00' that converts safely percent-encoded null bytes (%00) back to raw null bytes (\x00), contrary to the safe direction of all other charMap entries. This occurs only when AxiosURLSearchParams.toString() is called without an external encoder, or when a custom paramsSerializer delegates to the internal encoder. The standard Axios request flow via buildURL() is not affected because it uses its own encode function and passes it as an external encoder to AxiosURLSearchParams. The vulnerability has a CVSS v3.1 score of 3.7 (Low) with network attack vector and high attack complexity. Patched versions (1.15.1 and 0.31.1) remove the unsafe charMap entry.
Affected products
- Axios Axios <=1.15.0, <=0.31.0
Timeline
- 2026-04-24: disclosed
- 2026-05-05: advisory
- 2026-05-05: patched: Versions 1.15.1 and 0.31.1 released