Astrojs Node vulnerabilities
9 known vulnerabilities affecting astrojs/node.
Total CVEs
9
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
HIGH1MEDIUM7LOW1
Vulnerabilities
Page 1 of 1
CVE-2025-55303P1MEDIUMExploitedPoC≥ 0, < 9.1.12025-08-19
CVE-2025-55303 [MEDIUM] CWE-79 Astro allows unauthorized third-party images in _image endpoint
Astro allows unauthorized third-party images in _image endpoint
### Summary
In affected versions of `astro`, the image optimization endpoint in projects deployed with on-demand rendering allows images from unauthorized third-party domains to be served.
### Details
On-demand rendered sites built with Astro include an `/_image` endpoint which returns optimized versions of images.
The `/_image` endpo
ghsaosv
CVE-2026-25545P2MEDIUMPoC≥ 0, < 9.5.42026-02-23
CVE-2026-25545 [MEDIUM] CWE-918 Astro has Full-Read SSRF in error rendering via Host: header injection
Astro has Full-Read SSRF in error rendering via Host: header injection
### Summary
Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astro` or `500.astro`) are vulnerable to SSRF. If the `Host:` header is changed to an attacker's server, it will be fetched on `/500.html` and they can redirect this to any internal URL to read the response body throu
ghsaosv
CVE-2026-102984P3HIGH≥ 0, < 11.1.32026-09-30
CVE-2026-102984 [HIGH] CWE-248 Astro: Malformed port in the Host header can crash the Node adapter
Astro: Malformed port in the Host header can crash the Node adapter
## Summary
In the Astro Node adapter, a request whose `Host` header contains a malformed port (for example `example.com:65536` or `example.com:8080:8080`) produced an invalid request URL. The fallback intended to recover from an unparseable URL reused the same malformed host, so it failed again and raised an uncaught `TypeError:
ghsa
CVE-2026-27829P3MEDIUM≥ 9.0.0, < 9.5.42026-02-25
CVE-2026-27829 [MEDIUM] CWE-918 Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize
Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize
## Summary
A bug in Astro's image pipeline allows bypassing `image.domains` / `image.remotePatterns` restrictions, enabling the server to fetch content from unauthorized remote hosts.
## Details
Astro provides an `inferSize` option that fetches remote images at render time to deter
ghsaosv
CVE-2026-27729P3MEDIUM≥ 9.0.0, < 9.5.42026-02-25
CVE-2026-27729 [MEDIUM] CWE-770 Astro has memory exhaustion DoS due to missing request body size limit in Server Actions
Astro has memory exhaustion DoS due to missing request body size limit in Server Actions
## Summary
Astro server actions have no default request body size limit, which can lead to memory exhaustion DoS. A single large POST to a valid action endpoint can crash the server process on memory-constrained deployments.
## Details
On-demand rendered sites built with Astro can defi
ghsaosv
CVE-2026-29772P3MEDIUM≥ 0, < 10.0.02026-03-24
CVE-2026-29772 [MEDIUM] CWE-770 Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands
Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands
### Summary
Astro's Server Islands POST handler buffers and parses the full request body as JSON without enforcing a size limit. Because `JSON.parse()` allocates a V8 heap object for every element in the input, a crafted payload of many small JSON objects achieves ~15x memory amplification (wi
ghsaosv
CVE-2025-55207P4MEDIUM≥ 0, < 9.4.12025-08-15
CVE-2025-55207 [MEDIUM] CWE-601 @astrojs/node's trailing slash handling causes open redirect issue
@astrojs/node's trailing slash handling causes open redirect issue
### Summary
Following https://github.com/withastro/astro/security/advisories/GHSA-cq8c-xv66-36gw, there's still an Open Redirect vulnerability in a subset of Astro deployment scenarios.
### Details
Astro 5.12.8 fixed a case where `https://example.com//astro.build/press` would redirect to the external origin `//astro.build/press`
ghsaosv
CVE-2026-41322P4MEDIUM≥ 0, < 10.0.52026-04-23
CVE-2026-41322 [MEDIUM] CWE-525 Astro: Cache Poisoning due to incorrect error handling when if-match header is malformed
Astro: Cache Poisoning due to incorrect error handling when if-match header is malformed
### Summary
Requesting a static JS/CSS resource from the `_astro` path with an incorrect or malformed `if-match` header returns a `500` error with a one-year cache lifetime instead of `412` in some cases. As a result, all subsequent requests to that file — regardless of the `if-match` hea
ghsa
CVE-2026-59730P4LOW≥ 8.1.0, < 11.0.22026-07-20
CVE-2026-59730 [LOW] CWE-601 @astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
### Impact
With `trailingSlash: 'always'` configured, the `@astrojs/node` standalone server's static file handler appends a trailing slash to request paths and issues a `301` redirect. Paths beginning with `/\` (slash-backslash) were not recognized as internal paths, so the handle
ghsa