Denial of Service Vulnerability in AdonisJS Web Framework
CVE-2026-25762
7.5HIGH
What is CVE-2026-25762?
AdonisJS, a TypeScript-first web framework, experienced a denial of service (DoS) vulnerability before versions 10.1.3 and 11.0.0-next.9. This issue stems from the multipart file handling logic of the @adonisjs/bodyparser, which could lead to an unbounded accumulation of data in memory while processing file uploads. If exploited, this vulnerability may result in substantial memory usage and potential termination of the application process. Users are recommended to upgrade to the patched versions to ensure application stability and security.
Affected Version(s)
core < 10.1.3 < 10.1.3
core < 11.0.0-next.9 < 11.0.0-next.9
