Executive brief
@koa/router is a routing middleware for Koa web applications that handles request routing and middleware execution. A flaw in versions 14.0.0 to 14.x causes middleware registered via `.use()` to be silently skipped when the router prefix contains path parameters (like `:appId`). An attacker can bypass authentication, authorization, rate limiting, or input sanitization protections that rely on this middleware.
Technical details
The vulnerability is a flaw in how @koa/router v14.0.0 introduced the pathAsRegExp option in the Layer class, which defaults to true for `.use()` middleware. When pathAsRegExp is true, middleware paths containing parameters (e.g., `/:id`, `/:version`) are passed directly to `new RegExp()` instead of being processed through path-to-regexp. This causes the regex to fail, resulting in the middleware being silently skipped during route matching. No authentication is required to exploit this—it affects all routes under a parameterized prefix. The vulnerability is fixed in v15.0.0. An attacker can access protected routes without triggering the expected middleware, enabling bypasses of security controls depending on what that middleware enforces.
Affected products
- Koa.js @koa/router 14.0.0 to before 15.0.0
Timeline
- 2026-05-26: disclosed: Vulnerability published on OSV database
- 2025-08-05: other: GitHub issue #202 filed describing the regression
- 2025-09-04: other: Fix PR #206 submitted
- 2025-12-02: patched: Fix merged and released in v15.0.0