Koa
Vendor:
First CVE: Feb 12, 2025 · Active for 1 year
5
Total CVEs
More Total CVEs than 77% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Koa over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 12, 2025
17 months ago
Most Recent CVE
Feb 26, 2026
149 days ago
CVE Severity & Scoring
Koa5 CVEs
60%
40%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (40.0%)
Unknown0 (0.0%)
Required3 (60.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27959HIGH Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API performs naive parsing of the HTTP Host header, extracting | Feb 26, 2026 | 8.2 | 31 | NO | NO |
CVE-2025-8129MEDIUM A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP Header | Jul 25, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-25200HIGH Koa is expressive middleware for Node.js using ES2017 async functions. Prior to versions 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3, Koa uses an evil regex to parse the `X-Forwarded- | Feb 12, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-62595MEDIUM Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to before 3.0.3, a bypass to CVE-2025-8129 was discovered in th | Oct 21, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-32379MEDIUM Koa is expressive middleware for Node.js using ES2017 async functions. In koa < 2.16.1 and < 3.0.0-alpha.5, passing untrusted user input to ctx.redirect() even after sanitizing it, | Apr 9, 2025 | 6.1 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Koa
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0.0 | 3 | 6.4 | 0.4% | 0 | 0 |
| 2.16.2 | 1 | 6.1 | 0.3% | 0 | 0 |