OSS Support Hub / Web Framework

Node.js Web Framework MIT Latest: v3.2.0

Koa

Expressive HTTP middleware framework for Node.js using async functions

Project Health at a Glance

Live data from GitHub and npm, updated daily.

โญ
35.7K
GitHub Stars
๐Ÿ“ฆ
v3.2.0
Latest Release ยท 1 months ago
๐Ÿ”„
27d
Avg. Release Cadence
๐Ÿ›
38
Open Issues
๐Ÿ“…
1 months ago
Last Commit
โฌ‡๏ธ
7.8M
Weekly Downloads
๐Ÿ”’
5
Active CVEs

Data last fetched: 2026-05-15

Known Vulnerabilities

5 active CVEs reported via OSV.dev

Inefficient Regular Expression Complexity in koa

Published: 2025-02-12 Fixed in: 2.15.4

Koa has Host Header Injection via ctx.hostname

Published: 2026-02-26 Fixed in: 3.1.2

Koa Vulnerable to Open Redirect via Trailing Double-Slash (//) in back Redirect Logic

Published: 2025-10-21 Fixed in: 3.0.3

Koa Open Redirect via Referrer Header (User-Controlled)

Published: 2025-07-29 Fixed in: 2.16.2

Koajs vulnerable to Cross-Site Scripting (XSS) at ctx.redirect() function

Published: 2025-04-09 Fixed in: 2.16.1

Alternatives to Koa

Other Web Framework projects in the Node.js ecosystem worth evaluating.

Support Options for Koa

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Koa โ€” without relying on volunteer maintainers.

Talk to an Expert โ†’