Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22567 | Koa Open Redirect via Referrer Header (User-Controlled) |
Github GHSA |
GHSA-jgmv-j7ww-jx2x | Koa Open Redirect via Referrer Header (User-Controlled) |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 17 Sep 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:koajs:koa:*:*:*:*:*:node.js:*:* cpe:2.3:a:koajs:koa:3.0.0:-:*:*:*:node.js:*:* cpe:2.3:a:koajs:koa:3.0.0:alpha0:*:*:*:node.js:*:* cpe:2.3:a:koajs:koa:3.0.0:alpha1:*:*:*:node.js:*:* cpe:2.3:a:koajs:koa:3.0.0:alpha2:*:*:*:node.js:*:* cpe:2.3:a:koajs:koa:3.0.0:alpha3:*:*:*:node.js:*:* cpe:2.3:a:koajs:koa:3.0.0:alpha4:*:*:*:node.js:*:* cpe:2.3:a:koajs:koa:3.0.0:alpha5:*:*:*:node.js:*:* |
Fri, 25 Jul 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Koajs
Koajs koa |
|
| Vendors & Products |
Koajs
Koajs koa |
Fri, 25 Jul 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Jul 2025 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP Header Handler. The manipulation of the argument Referrer leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Title | KoaJS Koa HTTP Header response.js back redirect | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-07-25T12:01:53.033Z
Reserved: 2025-07-24T15:24:16.752Z
Link: CVE-2025-8129
Updated: 2025-07-25T12:01:33.460Z
Status : Analyzed
Published: 2025-07-25T05:15:36.980
Modified: 2025-09-17T14:38:37.743
Link: CVE-2025-8129
No data.
OpenCVE Enrichment
Updated: 2025-07-25T15:53:55Z
EUVD
Github GHSA