VDB
Sign up
CRITICAL

GHSA-593f-38f6-jp5m

Inefficient Regular Expression Complexity in koa

Quick fix

GHSA-593f-38f6-jp5m — koa: upgrade to the fixed version with the command below.

npm install koa@2.15.4

Details

### Summary Koa uses an evil regex to parse the `X-Forwarded-Proto` and `X-Forwarded-Host` HTTP headers. This can be exploited to carry out a Denial-of-Service attack.

### PoC

Coming soon.

### Impact This is a Regex Denial-of-Service attack and causes memory exhaustion. The regex should be improved and empty values should not be allowed.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/koa
Introduced in: 2.0.0Fixed in: 2.15.4
Fixnpm install koa@2.15.4
npm/koa
Introduced in: 3.0.0-alpha.0Fixed in: 3.0.0-alpha.3
Fixnpm install koa@3.0.0-alpha.3
npm/koa
Introduced in: 1.0.0Fixed in: 1.7.1
Fixnpm install koa@1.7.1
npm/koa
Introduced in: 0Fixed in: 0.21.2
Fixnpm install koa@0.21.2

References