Koa web app framework
92%
Total Score
62
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-27959 koa is vulnerable to Improper Input Validation in versions 3.0.0 - 3.1.2 and 0.0.0 - 2.16.4. | 0.0.0 - 2.16.43.0.0 - 3.1.2 | High |
AIKIDO-2025-10725 koa is vulnerable to Cross-Site Scripting (XSS) in versions 2.16.0 - 3.0.1. | 2.16.0 - 3.0.1 | Medium |
CVE-2025-62595 koa is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 3.0.1 - 3.0.3 and 2.16.2 - 2.16.3. | 2.16.2 - 2.16.33.0.1 - 3.0.3 | Medium |
CVE-2025-8129 koa is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 2.0.0 - 2.16.2 and 3.0.0-alpha.0 - 3.0.1. | 2.0.0 - 2.16.23.0.0-alpha.0 - 3.0.1 | Low |
CVE-2025-32379 koa is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.16.1 and 3.0.0-alpha.1 - 3.0.0-alpha.5. | 0.0.0 - 2.16.13.0.0-alpha.1 - 3.0.0-alpha.5 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
vary Version ^1.1.2 | — | — |
fresh Version ~0.5.2 | — | — |
accepts Version ^1.3.8 | — | — |
cookies Version ~0.9.1 | — | — |
destroy Version ^1.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant