CVE-2025-8129

A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP Header Handler. The manipulation of the argument Referrer leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://github.com/koajs/koa/issues/1892 Exploit Issue Tracking Patch Vendor Advisory
https://github.com/koajs/koa/issues/1892#issue-3213028583 Exploit Issue Tracking Patch Third Party Advisory Vendor Advisory
https://vuldb.com/?ctiid.317514 Permissions Required VDB Entry
https://vuldb.com/?id.317514 Third Party Advisory VDB Entry
https://vuldb.com/?submit.619741 Third Party Advisory VDB Entry
https://github.com/koajs/koa/issues/1892 Exploit Issue Tracking Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:koajs:koa:*:*:*:*:*:node.js:*:*
cpe:2.3:a:koajs:koa:3.0.0:-:*:*:*:node.js:*:*
cpe:2.3:a:koajs:koa:3.0.0:alpha0:*:*:*:node.js:*:*
cpe:2.3:a:koajs:koa:3.0.0:alpha1:*:*:*:node.js:*:*
cpe:2.3:a:koajs:koa:3.0.0:alpha2:*:*:*:node.js:*:*
cpe:2.3:a:koajs:koa:3.0.0:alpha3:*:*:*:node.js:*:*
cpe:2.3:a:koajs:koa:3.0.0:alpha4:*:*:*:node.js:*:*
cpe:2.3:a:koajs:koa:3.0.0:alpha5:*:*:*:node.js:*:*

History

17 Sep 2025, 14:38

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad clasificada como problemática en KoaJS (hasta la versión 3.0.0). La función afectada se encuentra en la librería lib/response.js del componente HTTP Header Handler. La manipulación del argumento Referrer provoca una redirección abierta. El ataque puede ejecutarse en remoto. Se ha hecho público el exploit y puede que sea utilizado.
CPE cpe:2.3:a:koajs:koa:3.0.0:alpha2:*:*:*:node.js:*:*
cpe:2.3:a:koajs:koa:3.0.0:-:*:*:*:node.js:*:*
cpe:2.3:a:koajs:koa:3.0.0:alpha0:*:*:*:node.js:*:*
cpe:2.3:a:koajs:koa:3.0.0:alpha3:*:*:*:node.js:*:*
cpe:2.3:a:koajs:koa:3.0.0:alpha1:*:*:*:node.js:*:*
cpe:2.3:a:koajs:koa:3.0.0:alpha4:*:*:*:node.js:*:*
cpe:2.3:a:koajs:koa:*:*:*:*:*:node.js:*:*
cpe:2.3:a:koajs:koa:3.0.0:alpha5:*:*:*:node.js:*:*
First Time Koajs koa
Koajs
References () https://github.com/koajs/koa/issues/1892 - () https://github.com/koajs/koa/issues/1892 - Exploit, Issue Tracking, Patch, Vendor Advisory
References () https://github.com/koajs/koa/issues/1892#issue-3213028583 - () https://github.com/koajs/koa/issues/1892#issue-3213028583 - Exploit, Issue Tracking, Patch, Third Party Advisory, Vendor Advisory
References () https://vuldb.com/?ctiid.317514 - () https://vuldb.com/?ctiid.317514 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.317514 - () https://vuldb.com/?id.317514 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.619741 - () https://vuldb.com/?submit.619741 - Third Party Advisory, VDB Entry

25 Jul 2025, 12:15

Type Values Removed Values Added
References () https://github.com/koajs/koa/issues/1892 - () https://github.com/koajs/koa/issues/1892 -

25 Jul 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-25 05:15

Updated : 2025-09-17 14:38


NVD link : CVE-2025-8129

Mitre link : CVE-2025-8129

CVE.ORG link : CVE-2025-8129


JSON object : View

Products Affected

koajs

  • koa
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')