CVE-2026-27959
- EPSS 0.12%
- Veröffentlicht 26.02.2026 01:45:45
- Zuletzt bearbeitet 28.02.2026 00:55:26
Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API performs naive parsing of the HTTP Host header, extracting everything before the first colon without validating the input conform...
CVE-2025-62595
- EPSS 0.02%
- Veröffentlicht 21.10.2025 16:20:43
- Zuletzt bearbeitet 20.01.2026 14:45:48
Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to before 3.0.3, a bypass to CVE-2025-8129 was discovered in the Koa.js framework affecting its back redirect functionality. In certa...
CVE-2025-8129
- EPSS 0.05%
- Veröffentlicht 25.07.2025 05:15:36
- Zuletzt bearbeitet 17.09.2025 14:38:37
A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP Header Handler. The manipulation of the argument Referrer leads to open redir...
CVE-2025-32379
- EPSS 0.18%
- Veröffentlicht 09.04.2025 16:15:25
- Zuletzt bearbeitet 14.01.2026 14:36:06
Koa is expressive middleware for Node.js using ES2017 async functions. In koa < 2.16.1 and < 3.0.0-alpha.5, passing untrusted user input to ctx.redirect() even after sanitizing it, may execute javascript code on the user who use the app. This issue i...
CVE-2025-25200
- EPSS 0.68%
- Veröffentlicht 12.02.2025 18:15:28
- Zuletzt bearbeitet 20.01.2026 14:42:45
Koa is expressive middleware for Node.js using ES2017 async functions. Prior to versions 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3, Koa uses an evil regex to parse the `X-Forwarded-Proto` and `X-Forwarded-Host` HTTP headers. This can be exploited to c...