Koa Host Header Injection Enables URL Manipulation
CVE-2026-27959 in Koa allows attackers to manipulate ctx.hostname via crafted Host headers, redirecting password resets and other sensitive links to malicious domains.
Source: Endor Labs
Read more: CyberSecBrief













