Package compatibility
Koa 2.2
What Node.js versions does this Koa version support?
Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.
Declared Node.js requirement
- engines.node
- >= 6.0.0
- Tip version
- 2.3.0
- Source
- npm Registry (engines.node)
Node.js compatibility matrix
Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.
Other Koa lines
Security
Advisories affecting Koa 2.2 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 2
- Known exploited
- 0
- Highest CVSS
- —
- CVE-2026-27959GHSA-7gcc-r8m5-44qm
Koa has Host Header Injection via ctx.hostname
- Affected:
- <2.16.4
- Fixed in:
- 2.16.4
- Source:
- OSV source · Advisory
- CVE-2025-32379GHSA-x2rg-q646-7m2v
Koajs vulnerable to Cross-Site Scripting (XSS) at ctx.redirect() function
- Affected:
- <2.16.1
- Fixed in:
- 2.16.1
- Source:
- OSV source · Advisory
