CVE-2026-27959
When a malformed Host header containing a `@` symbol is received, `ctx.hostname` returns `evil[.]com` - an attacker-controlled value.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API performs naive parsing of the HTTP Host header, extracting everything before the first colon without validating the input conforms to RFC 3986 hostname syntax. When a malformed Host header containing a `@` symbol is received, `ctx.hostname` returns `evil[.]com` - an attacker-controlled value. Applications using `ctx.hostname` for URL generation, password reset links, email verification URLs, or routing decisions are vulnerable to Host header injection attacks. Versions 3.1.2 and 2.16.4 fix the issue.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- koajs/koa
- Source
- security-advisories@github.com
References
- https://github.com/koajs/koa/commit/55ab9bab044ead4e82c70a30a4f9dc0fc9c1b6dfPatch
- https://github.com/koajs/koa/commit/b76ddc01fdb703e51652b0fd131d16394cadcfebPatch
- https://github.com/koajs/koa/security/advisories/GHSA-7gcc-r8m5-44qmExploit, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:10184
- https://access.redhat.com/errata/RHSA-2026:7249
- https://access.redhat.com/security/cve/CVE-2026-27959
- https://bugzilla.redhat.com/show_bug.cgi?id=2442928
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27959.json
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.