Package compatibility

Koa 2.1

What Node.js versions does this Koa version support?

Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.

Declared Node.js requirement

engines.node
>= 7.6.0
Tip version
2.1.0
Source
npm Registry (engines.node)

Node.js compatibility matrix

Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.

Other Koa lines

Security

Advisories affecting Koa 2.1 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
2
Known exploited
0
Highest CVSS
  • CVE-2026-27959GHSA-7gcc-r8m5-44qm

    Koa has Host Header Injection via ctx.hostname

    Affected:
    <2.16.4
    Fixed in:
    2.16.4
    Source:
    OSV source · Advisory
  • CVE-2025-32379GHSA-x2rg-q646-7m2v

    Koajs vulnerable to Cross-Site Scripting (XSS) at ctx.redirect() function

    Affected:
    <2.16.1
    Fixed in:
    2.16.1
    Source:
    OSV source · Advisory