Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silently dropped from the execution chain when the router prefix contains path parameters. Depending on what the skipped middleware was supposed to protect, an attacker could bypass authentication and authorization, evade rate limiting or bypass input sanitization.
History

Tue, 26 May 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 26 May 2026 07:45:00 +0000

Type Values Removed Values Added
Title Access Control Bypass in Koa Router Prefix Path Parameters

Tue, 26 May 2026 06:30:00 +0000

Type Values Removed Values Added
Description Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silently dropped from the execution chain when the router prefix contains path parameters. Depending on what the skipped middleware was supposed to protect, an attacker could bypass authentication and authorization, evade rate limiting or bypass input sanitization.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2026-05-26T05:00:04.704Z

Updated: 2026-05-26T12:41:21.925Z

Reserved: 2026-05-25T09:18:41.020Z

Link: CVE-2026-9495

cve-icon Vulnrichment

Updated: 2026-05-26T12:40:05.094Z

cve-icon NVD

Status : Received

Published: 2026-05-26T07:16:19.243

Modified: 2026-05-26T14:16:44.280

Link: CVE-2026-9495

cve-icon Redhat

No data.