CVE-2026-9495 PUBLISHED

Assigner: snyk
Reserved: 25.05.2026 Published: 26.05.2026 Updated: 26.05.2026

Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silently dropped from the execution chain when the router prefix contains path parameters. Depending on what the skipped middleware was supposed to protect, an attacker could bypass authentication and authorization, evade rate limiting or bypass input sanitization.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.9

Product Status

Vendor n/a
Product @koa/router
Versions
  • affected from 14.0.0 to 15.0.0 (excl.)

Credits

  • Ryan Mitchell

References

Problem Types

  • Access Control Bypass