Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/koa — 5 CVEs · VulnScope
pkg:npm/
koa
5 total CVEs
HIGH
1
MEDIUM
2
LOW
1
✅ Check your installed version
Check
All known vulnerabilities
HIGH
7.5
CVE-2026-27959
Koa has Host Header Injection via ctx.hostname
>= 3.0.0, < 3.1.2
MEDIUM
5.0
CVE-2025-32379
Koajs vulnerable to Cross-Site Scripting (XSS) at ctx.redirect() function
from 0, < 2.16.1
MEDIUM
4.7
CVE-2025-62595
Koa Vulnerable to Open Redirect via Trailing Double-Slash (//) in back Redirect Logic
>= 3.0.1, < 3.0.3
LOW
3.5
Koa Open Redirect via Referrer Header (User-Controlled)
>= 2.0.0, < 2.16.2
—
Inefficient Regular Expression Complexity in koa
>= 2.0.0, < 2.15.4
CVE-2025-8129
CVE-2025-25200