Koajs maintains a focused framework and middleware ecosystem for Node.js web applications, where its vulnerability exposure centers on a narrow set of core and CORS-related components. The durable signal across its disclosures reflects typical application-framework risks: open redirects, improper input validation, cross-site scripting, and regex-complexity issues that arise in HTTP request handling and header-parsing layers. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Koajs over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27959HIGH Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API performs naive parsing of the HTTP Host header, extracting | Feb 26, 2026 | 8.2 | 31 | NO | NO |
CVE-2025-8129MEDIUM A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP Header | Jul 25, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-25200HIGH Koa is expressive middleware for Node.js using ES2017 async functions. Prior to versions 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3, Koa uses an evil regex to parse the `X-Forwarded- | Feb 12, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-62595MEDIUM Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to before 3.0.3, a bypass to CVE-2025-8129 was discovered in th | Oct 21, 2025 | 6.1 | 21 | NO | NO |
CVE-2023-49803HIGH @koa/cors npm provides Cross-Origin Resource Sharing (CORS) for koa, a web framework for Node.js. Prior to version 5.0.0, the middleware operates in a way that if an allowed origin | Dec 11, 2023 | 7.5 | 20 | NO | NO |
CVE-2025-32379MEDIUM Koa is expressive middleware for Node.js using ES2017 async functions. In koa < 2.16.1 and < 3.0.0-alpha.5, passing untrusted user input to ctx.redirect() even after sanitizing it, | Apr 9, 2025 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Koajs.
Media articles that mention a CVE ID that affects a product developed by Koajs — matched by CVE ID, not by vendor name.