CRITICAL
GHSA-593f-38f6-jp5m
Inefficient Regular Expression Complexity in koa
Quick fix
GHSA-593f-38f6-jp5m — koa: upgrade to the fixed version with the command below.
npm install koa@2.15.4Details
### Summary Koa uses an evil regex to parse the `X-Forwarded-Proto` and `X-Forwarded-Host` HTTP headers. This can be exploited to carry out a Denial-of-Service attack.
### PoC
Coming soon.
### Impact This is a Regex Denial-of-Service attack and causes memory exhaustion. The regex should be improved and empty values should not be allowed.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/koajs/koa/security/advisories/GHSA-593f-38f6-jp5m[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-25200[ADVISORY]
- https://github.com/koajs/koa/commit/5054af6e31ffd451a4151a1fe144cef6e5d0d83c[WEB]
- https://github.com/koajs/koa/commit/5f294bb1c7c8d9c61904378d250439a321bffd32[WEB]
- https://github.com/koajs/koa/commit/93fe903fc966635a991bcf890cfc3427d33a1a08[WEB]
- https://github.com/koajs/koa[PACKAGE]
- https://github.com/koajs/koa/releases/tag/2.15.4[WEB]