---
id: CVE-2026-107718
title: >-
  AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS
  framework
summary: >-
  AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS
  framework. Prior to 8.2.3 and 9.3.0, AdonisJS HTTP Server inserts route
  parameter values into URLs without encodeURIComponent in the shared
  createURL() helper u…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-601
vendor: adonisjs
product: '@adonisjs/http-server'
affected:
  - '@adonisjs/http-server >= 9.0.0, <= 9.2.0'
  - '@adonisjs/http-server <= 8.2.2'
patched:
  - '@adonisjs/http-server 9.3.0'
  - '@adonisjs/http-server 8.2.3'
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:27.747'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107718'
references:
  - url: >-
      https://github.com/adonisjs/http-server/commit/4548a0631ce2ef1618f04c7b41465be42cad2f7d
    label: security-advisories@github.com
  - url: >-
      https://github.com/adonisjs/http-server/commit/ab607a2958327b6f0019d38f26081e431768877a
    label: security-advisories@github.com
  - url: 'https://github.com/adonisjs/http-server/releases/tag/v8.2.3'
    label: security-advisories@github.com
  - url: 'https://github.com/adonisjs/http-server/releases/tag/v9.3.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/adonisjs/http-server/security/advisories/GHSA-2m6q-8v3h-jqww
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-2m6q-8v3h-jqww'
tags:
  - nvd
  - ghsa
  - npm
aliases:
  - GHSA-2m6q-8v3h-jqww
ecosystem: npm
ingestedAt: '2026-10-08T22:11:53.871Z'
---

## Overview

AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. Prior to 8.2.3 and 9.3.0, AdonisJS HTTP Server inserts route parameter values into URLs without encodeURIComponent in the shared createURL() helper used by Router.makeUrl() and Response.redirect().toRoute(). If an application places attacker-controlled data in a dynamic first path segment and uses the generated route URL as a redirect destination, a value beginning with a slash can produce a scheme-relative external URL. Wildcard parameters are affected by the same missing encoding, while APIs intentionally accepting complete redirect URLs are not affected. An attacker can redirect users from a trusted application to an attacker-controlled site, facilitating phishing or abuse of authentication and OAuth flows. This issue is fixed in versions 8.2.3 and 9.3.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107718)

Affected packages:

- `@adonisjs/http-server >= 9.0.0, <= 9.2.0`
- `@adonisjs/http-server <= 8.2.2`

Patched in:

- `@adonisjs/http-server 9.3.0`
- `@adonisjs/http-server 8.2.3`

Source: https://github.com/advisories/GHSA-2m6q-8v3h-jqww
