← volver
CVE-2025-25200

Koa has Inefficient Regular Expression Complexity

CVSS 9.2 CRITICALEPSS 0.8%CWE-1333
Koa is expressive middleware for Node.js using ES2017 async functions. Prior to versions 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3, Koa uses an evil regex to parse the `X-Forwarded-Proto` and `X-Forwarded-Host` HTTP headers. This can be exploited to carry out a Denial-of-Service attack. Versions 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3 fix the issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Productos afectados
koajs · koa

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →