AION vulnerabilities
CVEs whose affected-version data names the AION package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-21833Low· 3.7HCL AION is affected by a vulnerability in which the Content-Security-Policy (CSP) HTTP response header is not configured
HCL AION is affected by a vulnerability in which the Content-Security-Policy (CSP) HTTP response header is not configured. CSP helps prevent attacks such as Cross-Site Scripting (XSS) by restricting the sources from which scripts, styles…
▾ SunlitHCL Software · AIONvia NVD
CVE-2025-52641Low· 2.9HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures
HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure of such information may provide insights into the underlying environment, which could potentially a…
▾ Sunlithcltech · aionEPSS 0.12%via NVD