NUL (Null) is ASCII code point 0 (0x00), Unicode U+0000, and the first C0 control character. It represents the absence of a character — a deliberate "nothing" byte. Its most familiar role is in C and C++, where 0x00 is the string terminator: every standard library function walks memory until it hits a NUL byte, which is why buffer overflows so often trace back to a missing '\0'. Most modern languages — Python, Java, Rust, Go — use length-prefixed strings, making NUL just another valid byte. It is not the same as NULL (the null pointer in C/C++), None in Python, or null in JavaScript and Java, which are language-level concepts for "no value." It originated as a no-op on teleprinters, used as idle fill on paper tape where the blank leader had all holes unpunched. UTF-8 encodes it as 0x00 except in Modified UTF-8 (Java's .class format), which uses the two-byte sequence 0xC0 0x80 to keep NUL out of C-style string handling. Unicode classifies it as Cc (Control) with the alias NULL.
char s[] = {'A','B','\0','C','D'}; // Embedded NUL in a byte arraysize_t n = strlen(s); // Stops at first NUL// n == 2, even though the array has more bytes
NUL (ASCII 0) marks the end of C-style strings. Every function like strlen or printf stops when it hits a NUL byte, making it the invisible fence post that tells programs where text ends and garbage begins.
No. POSIX file paths use NUL-terminated C strings internally, so the byte 0x00 is the one character you absolutely cannot put in a filename. URLs encode it as %00, but most servers reject it outright for security reasons.
Languages like Python, Java, and Go use length-prefixed strings instead of NUL termination, so 0x00 is just another valid byte to them. This avoids the truncation bugs that plague C code when binary data sneaks into string functions.
Not at all. NUL is a specific byte value (0x00) in a character set. The null keyword in Java or None in Python represents 'no object' — a concept, not a byte. Confusing the two is a common beginner mistake.
It's a security vulnerability where an attacker inserts %00 into a URL or input field. In vulnerable systems (often PHP or C-based web servers), this cuts off the string early, potentially bypassing file extension checks (e.g., 'image.jpg%00.php' becoming 'image.jpg').
A function or protocol is 'binary safe' if it can handle data containing NUL bytes without truncating or corrupting it. String functions in C are generally NOT binary safe; Python's strings ARE.