CVE-2025-32379: Koajs Koa

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Koa is expressive middleware for Node.js using ES2017 async functions. In koa < 2.16.1 and < 3.0.0-alpha.5, passing untrusted user input to ctx.redirect() even after sanitizing it, may execute javascript code on the user who use the app. This issue is patched in 2.16.1 and 3.0.0-alpha.5.

Affected products

  • Koajs Koa: before 2.16.1 (fixed in 2.16.1); version 3.0.0 only

Published 2025-04-09. Last modified 2026-06-17.