Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up

URL Percent Encoder & Decoder Studio

Encode and decode URL parameters, query strings, full URIs, and Base64URL strings with RFC 3986 compliance and diagnostics.

0 chars

⚠️ 5 Fatal Traps in URL Percent-Encoding & Parameter Routing

💥 1. 'encodeURI' vs. 'encodeURIComponent' Query Leakage

Using encodeURI() on user query parameters fails to encode &, =, and +. An input like "item&discount=100%" passed into encodeURI remains unescaped, splitting the query into unintended parameters (discount=100%) on the backend server. Always use encodeURIComponent() for parameter keys and values.

⚖️ 2. Double Percent-Encoding Attack (%252F WAF Bypass)

When an input is encoded twice, a slash / (%2F) becomes %252F. A web application firewall (WAF) inspects %252F, decodes %25 to %, sees %2F (non-path slash), and approves the request. The backend application server then decodes it a second time into a literal /, enabling critical path traversal (..%252F..%252Fetc%252Fpasswd).

🛡️ 3. Plus Sign '+' vs. '%20' Form-Urlencoded Inconsistency

Legacy HTML form post bodies (application/x-www-form-urlencoded) encode spaces as plus signs (+). However, standard RFC 3986 URI specifications encode spaces strictly as %20. Decoding a query string using standard decodeURIComponent() leaves literal + characters untouched instead of converting them back to spaces.

🔍 4. Uncaught 'URIError: URI malformed' Application Crashes

JavaScript's native decodeURIComponent() throws a fatal, unhandled URIError exception if the input contains a standalone percent sign (e.g. "100% satisfaction") or truncated multi-byte UTF-8 sequences (e.g. "%E0%A4"). A single unhandled malformed query parameter in server-side SSR can crash an entire Node.js worker process.

🚀 5. Path Traversal & Null Byte Poisoning (%00 & %5C)

Encoding directory separators (%2F, %5C) or null bytes (%00) bypasses superficial string validation (e.g. !path.includes('/')). If backend file loaders decode parameters without verifying canonical resolved paths via path.resolve(), attackers can read arbitrary system configurations and keys.

Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement