This repository was archived by the owner on Sep 14, 2025. It is now read-only.
fix(deps): update dependency koa to v2.16.2 [security] #821
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.12.1->2.16.2GitHub Vulnerability Alerts
CVE-2025-25200
Summary
Koa uses an evil regex to parse the
X-Forwarded-ProtoandX-Forwarded-HostHTTP headers. This can be exploited to carry out a Denial-of-Service attack.PoC
Coming soon.
Impact
This is a Regex Denial-of-Service attack and causes memory exhaustion. The regex should be improved and empty values should not be allowed.
CVE-2025-32379
Summary
In koa < 2.16.1 and < 3.0.0-alpha.5, passing untrusted user input to ctx.redirect() even after sanitizing it, may execute javascript code on the user who use the app.
Patches
This issue is patched in 2.16.1 and 3.0.0-alpha.5.
PoC
Coming soon...
Impact
CVE-2025-8129
Summary
In the latest version of Koa, the back method used for redirect operations adopts an insecure implementation, which uses the user-controllable referrer header as the redirect target.
Details
on the API document https://www.koajs.net/api/response#responseredirecturl-alt, we can see:
response.redirect(url, [alt])
however, the "back" method is insecure:
Referrer Header is User-Controlled.
PoC
there is a demo for POC:
Proof Of Concept
Impact
https://learn.snyk.io/lesson/open-redirect/
Release Notes
koajs/koa (koa)
v2.16.2Compare Source
What's Changed
Full Changelog: koajs/koa@v2.16.1...v2.16.2
v2.16.1Compare Source
fix: don't render redirect values in anchor ref
v2.16.0Compare Source
This is a backported release to fix core underlying issue with
HEADrequests when usinghttp2.createSecureServer. See discussion at https://github.com/koajs/koa/pull/1593 and https://github.com/koajs/koa/issues/1547.399cb6bv2.15.4Compare Source
Full Changelog: koajs/koa@2.15.3...2.15.4
Fix: avoid redos on host and protocol getter, see GHSA-593f-38f6-jp5m
v2.15.3Compare Source
v2.15.2Compare Source
v2.15.1Compare Source
v2.15.0Compare Source
v2.14.2Compare Source
v2.14.1Compare Source
v2.14.0Compare Source
v2.13.4Compare Source
v2.13.3Compare Source
v2.13.2Compare Source
v2.13.1Compare Source
==================
fixes
b5472f4] - fix: make ESM transpiled CommonJS play nice for TS folks, fix #1513 (#1518) (miwnwski <m@iwnw.ski>)68d97d6] - fix: fixed order of vulnerability disclosure addresses (niftylettuce <niftylettuce@gmail.com>)others
b4398f5] - correct verb tense in doc (#1512) (Matan Shavit <71092861+matanshavit@users.noreply.github.com>)39e1a5a] - fixed multiple grammatical errors in docs. (#1497) (Hridayesh Sharma <<vyasriday7@gmail.com>>)aeb5d19] - docs: added niftylettuce@gmail.com to vulnerability disclosure (niftylettuce <niftylettuce@gmail.com>)6e1093b] - docs: remove babel from readme (#1494) (miwnwski <m@iwnw.ski>)38cb591] - docs: update specific for auto response status (AlbertAZ1992 <ziyuximing@163.com>)2224cd9] - docs: remove babel ref. (#1488) (Imed Jaberi <imed_jebari@hotmail.fr>)d51f983] - docs: fix assert example for response (#1489) (Imed Jaberi <imed_jebari@hotmail.fr>)f8b49b8] - chore: fix grammatical and spelling errors in comments and tests (#1490) (Matt Kubej <mkubej@gmail.com>)d1c9263] - deps: update depd >> v2.0.0 (#1482) (imed jaberi <imed_jebari@hotmail.fr>)v2.13.0Compare Source
==================
features
bbcde76] - feat: support esm (#1474) (ZYSzys <zhangyongsheng@youzan.com>)others
20e58cf] - test: imporve coverage to 100% (dead-horse <dead_horse@qq.com>)4a40d63] - build: use prepare instead of prepublish (dead-horse <dead_horse@qq.com>)226ba8c] - build: use prepublish instead of prepack (dead-horse <dead_horse@qq.com>)Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.