Vulnerability record · CVE-2026-25762 · published 6 February 2026
CVE-2026-25762: Adonisjs bodyparser uncontrolled resource consumption vulnerability
Adonisjs · Bodyparser
AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a denial of service (DoS) vulnerability exists in the multipart file handling logic of @adonisjs/bodyparser. When processing file uploads, the multipart parser may accumulate an unbounded amount of data in memory while attempting to detect file types, potentially leading to excessive memory consumption and process termination. This issue has been patched in versions 10.1.3 and 11.0.0-next.9.
Description
AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a denial of service (DoS) vulnerability exists in the multipart file handling logic of @adonisjs/bodyparser. When processing file uploads, the multipart parser may accumulate an unbounded amount of data in memory while attempting to detect file types, potentially leading to excessive memory consumption and process termination. This issue has been patched in versions 10.1.3 and 11.0.0-next.9.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/adonisjs/bodyparser/releases/tag/v10.1.3 | Release Notes |
| https://github.com/adonisjs/bodyparser/releases/tag/v11.0.0-next.9 | Release Notes |
| https://github.com/adonisjs/core/security/advisories/GHSA-xx9g-fh25-4q64 | Third Party Advisory |
Track CVE-2026-25762 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-25762), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.