CVE-2025-52636

LOW

HCL AION is affected by a improper handling of uploads files Size

Title source: cna
STIX 2.1

Description

HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of upload sizes may allow excessive resource consumption, which could potentially lead to service degradation or denial-of-service conditions under certain scenarios.

Scores

CVSS v3 1.8
EPSS 0.0003
EPSS Percentile 8.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (2)
HCL/AION 2.0
hcltech/aion 2.0 - 2.1.2
Published Mar 16, 2026
Tracked Since Mar 16, 2026