Live data from GitHub and npm, updated daily.
Data last fetched: 2026-05-15
5 active CVEs reported via OSV.dev
Inefficient Regular Expression Complexity in koa
Koa has Host Header Injection via ctx.hostname
Koa Vulnerable to Open Redirect via Trailing Double-Slash (//) in back Redirect Logic
Koa Open Redirect via Referrer Header (User-Controlled)
Koajs vulnerable to Cross-Site Scripting (XSS) at ctx.redirect() function
Other Web Framework projects in the Node.js ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Koa โ without relying on volunteer maintainers.
Talk to an Expert โ