VYPR
High severity7.5NVD Advisory· Published Feb 12, 2025· Updated Jun 17, 2026

CVE-2025-25200

CVE-2025-25200

Description

Koa is expressive middleware for Node.js using ES2017 async functions. Prior to versions 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3, Koa uses an evil regex to parse the X-Forwarded-Proto and X-Forwarded-Host HTTP headers. This can be exploited to carry out a Denial-of-Service attack. Versions 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3 fix the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
koanpm
>= 2.0.0, < 2.15.42.15.4
koanpm
>= 3.0.0-alpha.0, < 3.0.0-alpha.33.0.0-alpha.3
koanpm
>= 1.0.0, < 1.7.11.7.1
koanpm
< 0.21.20.21.2

Affected products

6
  • Koajs/Koa5 versions
    cpe:2.3:a:koajs:koa:*:*:*:*:*:node.js:*:*+ 4 more
    • cpe:2.3:a:koajs:koa:*:*:*:*:*:node.js:*:*range: <0.21.2
    • cpe:2.3:a:koajs:koa:3.0.0:alpha0:*:*:*:node.js:*:*
    • cpe:2.3:a:koajs:koa:3.0.0:alpha1:*:*:*:node.js:*:*
    • cpe:2.3:a:koajs:koa:3.0.0:alpha2:*:*:*:node.js:*:*
    • (no CPE)range: < 0.21.2
  • ghsa-coords
    Range: >= 2.0.0, < 2.15.4

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.