CVE Feed

    Dashboard / CVE / CVE-2026-40255

    CVE-2026-40255

    AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In @adonisjs/http-server versions prior to 7.8.1 and 8.0.0-next.0 through 8.1.3, and @adonisjs/core versions prior to 7.4.0, the response.redirect().back() method reads the Referer header from the incoming HTTP request and redirects to that URL without validating the host.An attacker who can influence the Referer header can cause the application to redirect users to a malicious external site. This affects all AdonisJS applications that use response.redirect().back() or response.redirect('back'). This issue has been fixed in versions 7.8.1 and 8.2.0 and 7.4.0 of @adonisjs/core.

    Published:Apr 16, 2026
    Last Modified:Apr 27, 2026
    EPS:Apr 16, 2026
    EPSS Score:0.0001
    CVSS Score:6.1

    Affected Products

    Vendor
    Adonisjs
    Product
    Core
    Vendor
    Adonisjs
    Product
    Http-core
    Vendor
    Adonisjs
    Product
    Http-server

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High