Vulnerable Library - oidc-provider-8.8.1.tgz
Path to dependency file: /docker/development/mock-oidc-provider/package.json
Path to vulnerable library: /docker/development/mock-oidc-provider/node_modules/koa/package.json
Found in HEAD commit: 9d91325af8d6b6836292c4bb0ba361ab2cdf10e0
Vulnerabilities
| Vulnerability |
Severity |
CVSS |
Dependency |
Type |
Fixed in (oidc-provider version) |
Remediation Possible** |
| CVE-2025-8129 |
Low |
3.5 |
koa-2.16.4.tgz |
Transitive |
N/A* |
❌ |
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2025-8129
Vulnerable Library - koa-2.16.4.tgz
Koa web app framework
Library home page: https://registry.npmjs.org/koa/-/koa-2.16.4.tgz
Path to dependency file: /docker/development/mock-oidc-provider/package.json
Path to vulnerable library: /docker/development/mock-oidc-provider/node_modules/koa/package.json
Dependency Hierarchy:
- oidc-provider-8.8.1.tgz (Root Library)
- ❌ koa-2.16.4.tgz (Vulnerable Library)
Found in HEAD commit: 9d91325af8d6b6836292c4bb0ba361ab2cdf10e0
Found in base branch: main
Vulnerability Details
A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP Header Handler. The manipulation of the argument Referrer leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Publish Date: 2025-07-25
URL: CVE-2025-8129
CVSS 3 Score Details (3.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-jgmv-j7ww-jx2x
Release Date: 2025-07-25
Fix Resolution: koa - 3.0.1,koa - 2.16.2
Path to dependency file: /docker/development/mock-oidc-provider/package.json
Path to vulnerable library: /docker/development/mock-oidc-provider/node_modules/koa/package.json
Found in HEAD commit: 9d91325af8d6b6836292c4bb0ba361ab2cdf10e0
Vulnerabilities
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - koa-2.16.4.tgz
Koa web app framework
Library home page: https://registry.npmjs.org/koa/-/koa-2.16.4.tgz
Path to dependency file: /docker/development/mock-oidc-provider/package.json
Path to vulnerable library: /docker/development/mock-oidc-provider/node_modules/koa/package.json
Dependency Hierarchy:
Found in HEAD commit: 9d91325af8d6b6836292c4bb0ba361ab2cdf10e0
Found in base branch: main
Vulnerability Details
A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP Header Handler. The manipulation of the argument Referrer leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Publish Date: 2025-07-25
URL: CVE-2025-8129
CVSS 3 Score Details (3.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-jgmv-j7ww-jx2x
Release Date: 2025-07-25
Fix Resolution: koa - 3.0.1,koa - 2.16.2