
🚨 High - Koa Router Middleware Bypass via Prefix Path Parameters (CVE-2026-9495) When a @koa/router prefix contains path parameters, registered middleware is silently dropped from the execution chain, allowing attackers to bypass authentication, authorization, rate limiting, or input sanitization, depending on what the skipped middleware enforced. Network-reachable with no auth and no UI (CVSS 7.3). 👉 Affected: @koa/router 14.0.0 ≤ v < 15.0.0 | Upgrade to 15.0.0
Post summary
A CVSS 7.3 middleware bypass in @koa/router (v14.x) allows attackers to skip authentication or rate‑limiting, and users should upgrade to 15.0.0 to address the issue.
