CVE-2025-52636: Hcltech Aion
High severity, CVSS 7.5. EPSS: 0.1% chance of exploitation in the next 30 days.
HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of upload sizes may allow excessive resource consumption, which could potentially lead to service degradation or denial-of-service conditions under certain scenarios.
Affected products
- Hcltech Aion: from 2.0.0, before 2.1.2 (fixed in 2.1.2)
Published 2026-03-16. Last modified 2026-06-17.