mysocAi[verified]@MysocAiDisclosure
The post announces CVE-2026-27959, a host header injection vulnerability in Koa that enables manipulation of password reset URLs, highlighting the risk to web applications.
mysocAi[verified]@MysocAiDisclosure
The article announces a new host header injection vulnerability (CVE‑2026‑27959) that enables malicious URL generation via userinfo‑based host header injection, but it does not provide a PoC, exploit code, or patch details.
CRAC Learning - Tech@cracbotGeneral
The post references CVE-2026-27959, noting its CVSS score and affected Koa versions, but provides no PoC, exploit, patch, or active exploitation details.
cvereports@_cvereportsDisclosure
The report announces a high‑severity Host Header Injection vulnerability in the Koa framework that permits manipulation of context.hostname through malformed headers, but no PoC, exploit, or patch information is provided.
CVE@CVEnewDisclosure
CVE-2026-27959 describes a vulnerability in Koa's ctx.hostname API where naive parsing of the HTTP Host header can lead to issues, affecting versions prior to 3.1.2 and 2.16.4.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A new host header injection vulnerability (CVE-2026-27959) affecting Koa middleware has been disclosed, with details available on Vulmon.