{"api_version":"v1","generated_at":"2026-10-09T11:05:00+00:00","product":{"cve_count":4,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-koajs-koa-f91137cdf670","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/koa","name":"Koa","next_cursor":null,"observations":[{"affected":">= 3.0.0, < 3.1.2; < 2.16.4","affected_versions_present":true,"cve_id":"CVE-2026-27959","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27959","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-15T01:12:18.807Z","patch_url":"https://github.com/koajs/koa/commit/55ab9bab044ead4e82c70a30a4f9dc0fc9c1b6df","primary_source":"","published":"2026-02-26T01:45:45.668Z"},{"affected":"koa: >= 2.16.2, < 2.16.3, >= 3.0.1, < 3.0.3","affected_versions_present":true,"cve_id":"CVE-2025-62595","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-62595","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-10-21T16:35:48.461Z","patch_url":"https://github.com/koajs/koa/commit/769fd75cc6b30d72493b370b5a3ae2332ca03c5b","primary_source":"","published":"2025-10-21T16:20:43.809Z"},{"affected":"3.0","affected_versions_present":true,"cve_id":"CVE-2025-8129","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-8129","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-07-25T12:01:53.033Z","patch_url":"https://github.com/koajs/koa/issues/1892","primary_source":"","published":"2025-07-25T04:02:05.418Z"},{"affected":">= 3.0.0-alpha.0, < 3.0.0-alpha.5; < 2.16.1","affected_versions_present":true,"cve_id":"CVE-2025-32379","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32379","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-09T20:45:15.899Z","patch_url":"https://github.com/koajs/koa/security/advisories/GHSA-x2rg-q646-7m2v","primary_source":"","published":"2025-04-09T15:56:40.574Z"},{"affected":"< 0.21.2; >= 1.0.0, < 1.7.1; >= 2.0.0-alpha.1, < 2.15.4; >= 3.0.0-alpha.0, < < 3.0.0-alpha.3","affected_versions_present":true,"cve_id":"CVE-2025-25200","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-25200","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-12T19:29:10.232Z","patch_url":"https://github.com/koajs/koa/commit/5054af6e31ffd451a4151a1fe144cef6e5d0d83c","primary_source":"","published":"2025-02-12T17:59:04.615Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"KoaJS"}}
