CVE-2026-9495Patch

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silently dropped from the execution chain when the router prefix contains path parameters. Depending on what the skipped middleware was supposed to protect, an attacker could bypass authentication and authorization, evade rate limiting or bypass input sanitization.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-26: 1Patch / Workaround · 2026-05-26: 1Technical Details · 2026-05-26: 105-26
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 High - Koa Router Middleware Bypass via Prefix Path Parameters (CVE-2026-9495) When a @koa/router prefix contains path parameters, registered middleware is silently dropped from the execution chain, allowing attackers to bypass authentication, authorization, rate limiting, or input sanitization, depending on what the skipped middleware enforced. Network-reachable with no auth and no UI (CVSS 7.3). 👉 Affected: @koa/router 14.0.0 ≤ v < 15.0.0 | Upgrade to 15.0.0

    Post summary

    A CVSS 7.3 middleware bypass in @koa/router (v14.x) allows attackers to skip authentication or rate‑limiting, and users should upgrade to 15.0.0 to address the issue.

    0000082
    196 followersView on X

Explore more