Adacore maintains a specialized portfolio of Ada language tools and web-oriented libraries, including the Ada Web Server and Ada Web Services, which serve a focused domain within embedded systems and safety-critical software development. Vulnerabilities affecting this vendor cluster around resource-management and input-handling weaknesses—including unbounded resource allocation, certificate validation issues, and insufficient input filtering—which are characteristic of network-facing server components. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Adacore over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-52494HIGH Adacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling of SSL handshakes during connection initialization. When a cl | Sep 3, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-55581HIGH When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTP | Feb 26, 2025 | 7.4 | 20 | NO | NO |
CVE-2012-1035MEDIUM AdaCore Ada Web Services (AWS) before 2.10.2 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote at | Feb 8, 2012 | 5.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Adacore.
Media articles that mention a CVE ID that affects a product developed by Adacore — matched by CVE ID, not by vendor name.