Live data from GitHub and npm, updated daily.
Data last fetched: 2026-06-29
5 active CVEs reported via OSV.dev
Inefficient Regular Expression Complexity in koa
Koa has Host Header Injection via ctx.hostname
Koa Vulnerable to Open Redirect via Trailing Double-Slash (//) in back Redirect Logic
Koa Open Redirect via Referrer Header (User-Controlled)
Koajs vulnerable to Cross-Site Scripting (XSS) at ctx.redirect() function
Get SLA-backed support, security patches, and direct access to senior engineers for Koa — without relying on volunteer maintainers.