cbcvebase.

Astrojs Node vulnerabilities

9 known vulnerabilities affecting astrojs/node.

Total CVEs
9
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
HIGH1MEDIUM7LOW1

Vulnerabilities

Page 1 of 1
CVE-2025-55303P1MEDIUMExploitedPoC≥ 0, < 9.1.12025-08-19
CVE-2025-55303 [MEDIUM] CWE-79 Astro allows unauthorized third-party images in _image endpoint Astro allows unauthorized third-party images in _image endpoint ### Summary In affected versions of `astro`, the image optimization endpoint in projects deployed with on-demand rendering allows images from unauthorized third-party domains to be served. ### Details On-demand rendered sites built with Astro include an `/_image` endpoint which returns optimized versions of images. The `/_image` endpo
ghsaosv
CVE-2026-25545P2MEDIUMPoC≥ 0, < 9.5.42026-02-23
CVE-2026-25545 [MEDIUM] CWE-918 Astro has Full-Read SSRF in error rendering via Host: header injection Astro has Full-Read SSRF in error rendering via Host: header injection ### Summary Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astro` or `500.astro`) are vulnerable to SSRF. If the `Host:` header is changed to an attacker's server, it will be fetched on `/500.html` and they can redirect this to any internal URL to read the response body throu
ghsaosv
CVE-2026-102984P3HIGH≥ 0, < 11.1.32026-09-30
CVE-2026-102984 [HIGH] CWE-248 Astro: Malformed port in the Host header can crash the Node adapter Astro: Malformed port in the Host header can crash the Node adapter ## Summary In the Astro Node adapter, a request whose `Host` header contains a malformed port (for example `example.com:65536` or `example.com:8080:8080`) produced an invalid request URL. The fallback intended to recover from an unparseable URL reused the same malformed host, so it failed again and raised an uncaught `TypeError:
ghsa
CVE-2026-27829P3MEDIUM≥ 9.0.0, < 9.5.42026-02-25
CVE-2026-27829 [MEDIUM] CWE-918 Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize ## Summary A bug in Astro's image pipeline allows bypassing `image.domains` / `image.remotePatterns` restrictions, enabling the server to fetch content from unauthorized remote hosts. ## Details Astro provides an `inferSize` option that fetches remote images at render time to deter
ghsaosv
CVE-2026-27729P3MEDIUM≥ 9.0.0, < 9.5.42026-02-25
CVE-2026-27729 [MEDIUM] CWE-770 Astro has memory exhaustion DoS due to missing request body size limit in Server Actions Astro has memory exhaustion DoS due to missing request body size limit in Server Actions ## Summary Astro server actions have no default request body size limit, which can lead to memory exhaustion DoS. A single large POST to a valid action endpoint can crash the server process on memory-constrained deployments. ## Details On-demand rendered sites built with Astro can defi
ghsaosv
CVE-2026-29772P3MEDIUM≥ 0, < 10.0.02026-03-24
CVE-2026-29772 [MEDIUM] CWE-770 Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands ### Summary Astro's Server Islands POST handler buffers and parses the full request body as JSON without enforcing a size limit. Because `JSON.parse()` allocates a V8 heap object for every element in the input, a crafted payload of many small JSON objects achieves ~15x memory amplification (wi
ghsaosv
CVE-2025-55207P4MEDIUM≥ 0, < 9.4.12025-08-15
CVE-2025-55207 [MEDIUM] CWE-601 @astrojs/node's trailing slash handling causes open redirect issue @astrojs/node's trailing slash handling causes open redirect issue ### Summary Following https://github.com/withastro/astro/security/advisories/GHSA-cq8c-xv66-36gw, there's still an Open Redirect vulnerability in a subset of Astro deployment scenarios. ### Details Astro 5.12.8 fixed a case where `https://example.com//astro.build/press` would redirect to the external origin `//astro.build/press`
ghsaosv
CVE-2026-41322P4MEDIUM≥ 0, < 10.0.52026-04-23
CVE-2026-41322 [MEDIUM] CWE-525 Astro: Cache Poisoning due to incorrect error handling when if-match header is malformed Astro: Cache Poisoning due to incorrect error handling when if-match header is malformed ### Summary Requesting a static JS/CSS resource from the `_astro` path with an incorrect or malformed `if-match` header returns a `500` error with a one-year cache lifetime instead of `412` in some cases. As a result, all subsequent requests to that file — regardless of the `if-match` hea
ghsa
CVE-2026-59730P4LOW≥ 8.1.0, < 11.0.22026-07-20
CVE-2026-59730 [LOW] CWE-601 @astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect @astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect ### Impact With `trailingSlash: 'always'` configured, the `@astrojs/node` standalone server's static file handler appends a trailing slash to request paths and issues a `301` redirect. Paths beginning with `/\` (slash-backslash) were not recognized as internal paths, so the handle
ghsa
Astrojs Node vulnerabilities | cvebase