Astrojs Netlify vulnerabilities
2 known vulnerabilities affecting astrojs/netlify.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-102983P3MEDIUMCVSS 6.3v>= 5.2.0, < 8.2.42026-09-30
CVE-2026-102983 [MEDIUM] CWE-625 CVE-2026-102983: Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify a
Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL. Because Netlify evaluates these expressions with RegExp.test(), an allowed origin appearing only in a source URL's
ghsanvd
CVE-2026-54300P4MEDIUMCVSS 5.3≥ 0, < 7.0.132026-06-16
CVE-2026-54300 [MEDIUM] CWE-918 @astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config
@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config
## Summary
`@astrojs/netlify` converts Astro `image.remotePatterns` into Netlify Image CDN `images.remote_images` regular expressions with broader semantics than Astro's canonical matcher. A single wildcard hostname such as `*.example.com` is converted to an optional subdomain regex, so the apex host ma
ghsa