Adonisjs is a Node.js web application framework whose vulnerability exposure centers on its core HTTP handling, body-parsing, and prototype-manipulation mechanisms, reflected in recurring weaknesses including type confusion, prototype pollution, open redirects, and resource-consumption issues. These weakness classes are characteristic of JavaScript framework layers that process and transform user input across request routing and serialization boundaries, and defenders should track framework updates as part of their Node.js application supply chain. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Adonisjs over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25762HIGH AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a denial of service (DoS) vulnerability exists in the multipart file handling logic of @ad | Feb 6, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-25754HIGH AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a prototype pollution vulnerability in AdonisJS multipart form-data parsing may allow a re | Feb 6, 2026 | 7.2 | 25 | NO | NO |
CVE-2026-40255MEDIUM AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In @adonisjs/http-server versions prior to 7.8.1 and 8.0.0-next.0 through 8.1.3, and @adonis | Apr 16, 2026 | 6.1 | 21 | NO | NO |
CVE-2021-23443MEDIUM This affects the package edge.js before 5.3.2. A type confusion vulnerability can be used to bypass input sanitization when the input to be rendered is an array (instead of a strin | Sep 21, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Adonisjs.
Media articles that mention a CVE ID that affects a product developed by Adonisjs — matched by CVE ID, not by vendor name.