KoaJS Koa HTTP Header response.js back redirect
Published Jul 25, 2025
5.1
MEDIUMCVSS 4.0
EPSS 0.24%
Description
A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP Header Handler. The manipulation of the argument Referrer leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected products
-
- Version 3.0StatusaffectedConstraints-
- Version
No data.
OpenShift Service Mesh 2
openshift-service-mesh/grafana-rhel8
Fix deferred
OpenShift Service Mesh 2
openshift-service-mesh/istio-cni-rhel8
Fix deferred
OpenShift Service Mesh 2
openshift-service-mesh/istio-must-gather-rhel9
Fix deferred
OpenShift Service Mesh 2
openshift-service-mesh/istio-operator-bundle
Fix deferred
OpenShift Service Mesh 2
openshift-service-mesh/istio-rhel8-operator
Fix deferred
OpenShift Service Mesh 2
openshift-service-mesh/pilot-rhel8
Fix deferred
OpenShift Service Mesh 2
openshift-service-mesh/proxyv2-rhel9
Fix deferred
OpenShift Service Mesh 2
openshift-service-mesh/ratelimit-rhel8
Fix deferred
OpenShift Service Mesh 3
openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9
Fix deferred
OpenShift Service Mesh 3
openshift-service-mesh-tech-preview/istio-ztunnel-rhel9
Fix deferred
OpenShift Service Mesh 3
openshift-service-mesh/istio-cni-rhel9
Fix deferred
OpenShift Service Mesh 3
openshift-service-mesh/istio-must-gather-rhel9
Fix deferred
OpenShift Service Mesh 3
openshift-service-mesh/istio-pilot-rhel9
Fix deferred
OpenShift Service Mesh 3
openshift-service-mesh/istio-proxyv2-rhel9
Fix deferred
OpenShift Service Mesh 3
openshift-service-mesh/istio-rhel9-operator
Fix deferred
OpenShift Service Mesh 3
openshift-service-mesh/istio-sail-operator-bundle
Fix deferred
Red Hat Developer Hub
rhdh/rhdh-hub-rhel9
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/code-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 2 | openshift-service-mesh/grafana-rhel8 | Fix deferred | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/istio-cni-rhel8 | Fix deferred | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/istio-must-gather-rhel9 | Fix deferred | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/istio-operator-bundle | Fix deferred | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/istio-rhel8-operator | Fix deferred | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/pilot-rhel8 | Fix deferred | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/proxyv2-rhel9 | Fix deferred | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/ratelimit-rhel8 | Fix deferred | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9 | Fix deferred | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh-tech-preview/istio-ztunnel-rhel9 | Fix deferred | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/istio-cni-rhel9 | Fix deferred | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/istio-must-gather-rhel9 | Fix deferred | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/istio-pilot-rhel9 | Fix deferred | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/istio-proxyv2-rhel9 | Fix deferred | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/istio-rhel9-operator | Fix deferred | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/istio-sail-operator-bundle | Fix deferred | n/a |
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/code-rhel9 | Fix deferred | n/a |
koa
npm
Introduced 2.0.0 Fixed 2.16.2koa
npm
Introduced 3.0.0-alpha.0 Fixed 3.0.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | koa | 2.0.0 | 2.16.2 |
| npm | koa | 3.0.0-alpha.0 | 3.0.1 |
Remediation
Red Hat statement
To exploit this flaw, an attacker needs to convince a user into visiting a malicious link, limiting the possibility of exploitation. However, this vulnerability still has a moderate severity due to the impact of redirect-based attacks.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (14)
- https://access.redhat.com/security/cve/CVE-2025-8129 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2383344 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-22567 Advisory
- https://github.com/advisories/GHSA-jgmv-j7ww-jx2x Advisory
- https://github.com/koajs/koa/commit/422c551c63d00f24e2bbbdf492f262a5935bb1f0
- https://github.com/koajs/koa/issues/1892 exploitissue-trackingIssue TrackingPatchVendor Advisory
- https://github.com/koajs/koa/issues/1892#issue-3213028583 exploitissue-trackingIssue TrackingPatchThird Party AdvisoryVendor Advisory
- https://github.com/koajs/koa/security/advisories/GHSA-jgmv-j7ww-jx2x
- https://nvd.nist.gov/vuln/detail/CVE-2025-54420
- https://nvd.nist.gov/vuln/detail/CVE-2025-8129
- https://vuldb.com/?ctiid.317514 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.317514 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.619741 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.cve.org/CVERecord?id=CVE-2025-8129
Change history (0)
No recorded changes yet.