← Back

CVE-2025-8129

nvd nist
Published: Jul 25, 2025Modified: Jun 17, 2026

JSON object

Loading...
2.0
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: CNA (Secondary)

Description

A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP Header Handler. The manipulation of the argument Referrer leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Affected (8)

Products: Koajs: Koa
1 product
Koa
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Koajs
From 2.0.0 to 2.16.2
Version 3.0.0
Version 3.0.0 alpha0
Version 3.0.0 alpha1
Version 3.0.0 alpha2
Version 3.0.0 alpha3
Version 3.0.0 alpha4
Version 3.0.0 alpha5

References (6)

Source: cna@vuldb.com
ExploitIssue TrackingPatchVendor Advisory
Source: cna@vuldb.com
ExploitIssue TrackingPatchThird Party AdvisoryVendor Advisory
Source: cna@vuldb.com
Permissions RequiredVDB Entry
Source: cna@vuldb.com
Third Party AdvisoryVDB Entry
Source: cna@vuldb.com
Third Party AdvisoryVDB Entry
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitIssue TrackingPatchVendor Advisory

Timeline

No history available yet.