VYPR
Critical severityNVD Advisory· Published Feb 12, 2025· Updated Feb 12, 2025

Koa has Inefficient Regular Expression Complexity

CVE-2025-25200

Description

Koa is expressive middleware for Node.js using ES2017 async functions. Prior to versions 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3, Koa uses an evil regex to parse the X-Forwarded-Proto and X-Forwarded-Host HTTP headers. This can be exploited to carry out a Denial-of-Service attack. Versions 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3 fix the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
koanpm
>= 2.0.0, < 2.15.42.15.4
koanpm
>= 3.0.0-alpha.0, < 3.0.0-alpha.33.0.0-alpha.3
koanpm
>= 1.0.0, < 1.7.11.7.1
koanpm
< 0.21.20.21.2

Affected products

2

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.