CVE-2025-52636: Hcltech Aion

High severity, CVSS 7.5. EPSS: 0.1% chance of exploitation in the next 30 days.

HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of upload sizes may allow excessive resource consumption, which could potentially lead to service degradation or denial-of-service conditions under certain scenarios.

Affected products

  • Hcltech Aion: from 2.0.0, before 2.1.2 (fixed in 2.1.2)

Published 2026-03-16. Last modified 2026-06-17.