Metrics
Affected Vendors & Products
Sat, 22 Feb 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 21 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
threat_severity
|
cvssV3_1
|
Fri, 21 Feb 2025 02:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Wed, 12 Feb 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 12 Feb 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Koa is expressive middleware for Node.js using ES2017 async functions. Prior to versions 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3, Koa uses an evil regex to parse the `X-Forwarded-Proto` and `X-Forwarded-Host` HTTP headers. This can be exploited to carry out a Denial-of-Service attack. Versions 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3 fix the issue. | |
Title | Koa has Inefficient Regular Expression Complexity | |
Weaknesses | CWE-1333 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-02-12T17:59:04.615Z
Updated: 2025-02-12T19:29:10.232Z
Reserved: 2025-02-03T19:30:53.400Z
Link: CVE-2025-25200

Updated: 2025-02-12T19:29:02.600Z

Status : Received
Published: 2025-02-12T18:15:28.110
Modified: 2025-02-12T18:15:28.110
Link: CVE-2025-25200
