CVE-2026-25762Disclosure(adonisjs / bodyparser)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a denial of service (DoS) vulnerability exists in the multipart file handling logic of @adonisjs/bodyparser. When processing file uploads, the multipart parser may accumulate an unbounded amount of data in memory while attempting to detect file types, potentially leading to excessive memory consumption and process termination. This issue has been patched in versions 10.1.3 and 11.0.0-next.9.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bodyparser

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-06); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
bodyparser

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-06: 1Mentions · 2026-02-08: 1Mentions · 2026-02-16: 1Technical Details · 2026-02-06: 1Technical Details · 2026-02-08: 102-0602-0802-16
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-061
Disclosure1
2026-02-081
Disclosure1
2026-02-161
General1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25762 AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a denial of service (DoS) vulnerability exists in the multipart file handlin… https://www.cve.org/CVERecord?id=CVE-2026-25762

    Post summary

    CVE-2026-25762 is a denial of service vulnerability in AdonisJS’s multipart file handling, affecting versions prior to 10.1.3 and 11.0.0-next.9.

    00010275
    56.5K followersView on X
  • 0XJacks 𝕏@ZeroXJacks
    General

    https://github.com/ZeroXJacks/CVEs/blob/main/CVE-2026-25762.md https://nvd.nist.gov/vuln/detail/CVE-2026-25762 https://t.co/E4PEm6xtn7

    Post summary

    The text includes links to a CVE description and NVD entry but offers no explicit details, PoC, exploit code, or mitigation information.

    0000028
    6 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25762: Infinite Stream of Death: Crashing AdonisJS with Unbounded Buffers A classic but devastating Denial of Service vulnerability in the AdonisJS framework's `@adonisjs/bodyparser` package. By exploiting the multipart file parser's eagernes... https://cvereports.com/reports/CVE-2026-25762

    Post summary

    CVE-2026-25762 is a denial‑of‑service flaw in AdonisJS’s bodyparser due to unbounded buffers in multipart parsing; no PoC, exploit, or patch details are provided.

    0000050
    27 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
Appadonisjsbodyparser-node.js-
Appadonisjsbodyparser11.0.0node.js-
Appadonisjsbodyparser11.0.0node.js-
Appadonisjsbodyparser11.0.0node.js-
Appadonisjsbodyparser11.0.0node.js-
Appadonisjsbodyparser11.0.0node.js-
Appadonisjsbodyparser11.0.0node.js-
Appadonisjsbodyparser11.0.0node.js-
Appadonisjsbodyparser11.0.0node.js-

Explore more