cbcvebase.

Withastro Astro vulnerabilities

35 known vulnerabilities affecting withastro/astro.

Total CVEs
35
CISA KEV
0
Public exploits
5
Exploited in wild
3
Severity breakdown
CRITICAL1HIGH7MEDIUM23LOW4

Vulnerabilities

Page 1 of 2
CVE-2025-55303P1MEDIUMCVSS 6.1ExploitedPoCv>= 5.0.0-alpha.0, < 5.13.2fixed in 4.16.182025-08-19
CVE-2025-55303 [MEDIUM] CWE-79 CVE-2025-55303: Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18 Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimization endpoint in projects deployed with on-demand rendering allows images from unauthorized third-party domains to be served. On-demand rendered sites built with Astro include an /_image endpoint which returns optimized versions of
nvd
CVE-2024-56159P1MEDIUMCVSS 5.3ExploitedPoCv>= 5.0.0, < 5.0.8fixed in 4.16.182024-12-19
CVE-2024-56159 [MEDIUM] CWE-219 CVE-2024-56159: Astro is a web framework for content-driven websites. A bug in the build process allows any unauthen Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read parts of the server source code. During build, along with client assets such as css and font files, the sourcemap files **for the server code** are moved to a publicly-accessible folder. Any outside party can read them with an una
nvd
CVE-2025-64764P2MEDIUMCVSS 5.4ExploitedPoCfixed in 5.15.82025-11-19
CVE-2025-64764 [MEDIUM] CWE-80 CVE-2025-64764: Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feature is used in the targeted application, regardless of what was intended by the component template(s). This issue has been patched in version 5.15.8.
nvd
CVE-2026-25545P2HIGHCVSS 8.6PoCfixed in 9.5.42026-02-24
CVE-2026-25545 [HIGH] CWE-918 CVE-2026-25545: Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error wi Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astro` or `500.astro`) are vulnerable to SSRF. If the `Host:` header is changed to an attacker's server, it will be fetched on `/500.html` and they can redirect this to any internal URL to read the response b
nvd
CVE-2026-33768P2CRITICALCVSS 9.1fixed in 10.0.22026-03-24
CVE-2026-33768 [CRITICAL] CWE-441 CVE-2026-33768: Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads t Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path header and x_astro_path query parameter to rewrite the internal request path, with no authentication whatsoever. On deployments without Edge Middleware, this lets anyone bypass Vercel's platform-level path restrictions entirely. The
nvd
CVE-2025-54793P3MEDIUMCVSS 6.1PoCfixed in 9.4.12025-08-08
CVE-2025-54793 [MEDIUM] CWE-601 CVE-2025-54793: Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulnerability in the trailing slash redirection logic when handling paths with double slashes. This allows an attacker to redirect users to arbitrary external domains by crafting URLs such as https://mydomain.com//malicious-site.com/. Thi
nvd
CVE-2026-102984P3HIGHCVSS 8.2fixed in 11.1.32026-09-30
CVE-2026-102984 [HIGH] CWE-248 CVE-2026-102984: Astro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter bui Astro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter builds a request URL from the Host header, and a malformed port can make that URL invalid. The recovery path reuses the same malformed host and throws an uncaught TypeError: Invalid URL before routing begins. In the default standalone configuration, the
nvd
CVE-2026-59731P3HIGHCVSS 8.2v>= 6.4.7, < 6.4.82026-07-08
CVE-2026-59731 [HIGH] CWE-647 CVE-2026-59731: Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially decoded pathname after reaching the iterative URL decoder limit, while later rewrite route matching performs an additional decodeURI() operation and can resolve the request to a protected route. This issue is fixed in version 6.4.8.
nvd
CVE-2026-27829P3HIGHCVSS 7.2v>= 9.0.0, < 9.5.42026-02-26
CVE-2026-27829 [HIGH] CWE-918 CVE-2026-27829: Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in Astro's image pipeline allows by Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in Astro's image pipeline allows bypassing `image.domains` / `image.remotePatterns` restrictions, enabling the server to fetch content from unauthorized remote hosts. Astro provides an `inferSize` option that fetches remote images at render time to determine their dimensions. Remote imag
nvd
CVE-2026-27729P3HIGHCVSS 7.5v>= 9.0.0, < 9.5.42026-02-24
CVE-2026-27729 [HIGH] CWE-770 CVE-2026-27729: Astro is a web framework. In versions 9.0.0 through 9.5.3, Astro server actions have no default requ Astro is a web framework. In versions 9.0.0 through 9.5.3, Astro server actions have no default request body size limit, which can lead to memory exhaustion DoS. A single large POST to a valid action endpoint can crash the server process on memory-constrained deployments. On-demand rendered sites built with Astro can define server actions, which autom
nvd
CVE-2026-84376P3MEDIUMCVSS 6.3fixed in 7.2.42026-09-02
CVE-2026-84376 [MEDIUM] CWE-187 CVE-2026-84376: Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured no Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path from request pathnames using a string-prefix check without verifying a path-segment boundary. With base "/app", a request to "/appX/admin" resolved internally to the protected "/admin" route while middleware observed "/appX/admin" in
nvd
CVE-2026-102983P3MEDIUMCVSS 6.3v>= 5.2.0, < 8.2.42026-09-30
CVE-2026-102983 [MEDIUM] CWE-625 CVE-2026-102983: Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify a Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL. Because Netlify evaluates these expressions with RegExp.test(), an allowed origin appearing only in a source URL's
nvd
CVE-2026-54299P3HIGHCVSS 7.5fixed in 6.4.62026-06-22
CVE-2026-54299 [HIGH] CWE-20 CVE-2026-54299: Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const prerender = true) fetch those pages over HTTP at runtime when an error occurs. The URL for this fetch is derived from request.url, which in turn gets its origin from the incoming Host header. When the Host header is not validated agains
nvd
CVE-2026-29772P3HIGHCVSS 7.5fixed in 10.0.02026-03-24
CVE-2026-29772 [HIGH] CWE-770 CVE-2026-29772: Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and p Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full request body as JSON without enforcing a size limit. Because JSON.parse() allocates a V8 heap object for every element in the input, a crafted payload of many small JSON objects achieves ~15x memory amplification (wire bytes to heap bytes
nvd
CVE-2026-73424P3MEDIUMCVSS 6.5v>= 10.0.3, < 11.0.32026-08-17
CVE-2026-73424 [MEDIUM] CWE-441 CVE-2026-73424: Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel ada Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/integrations/vercel/src/serverless/entrypoint.ts accepts x_astro_path for the public /_isr function based only on the x-vercel-isr header, allowing unauthenticated GET requests to render routes protected only by Vercel edge path rules
nvd
CVE-2025-61925P3MEDIUMCVSS 6.5v>= 2.16.0, < 5.15.52025-10-10
CVE-2025-61925 [MEDIUM] CWE-470 CVE-2025-61925: Astro is a web framework. Prior to version 5.14.2, Astro reflects the value in `X-Forwarded-Host` in Astro is a web framework. Prior to version 5.14.2, Astro reflects the value in `X-Forwarded-Host` in output when using `Astro.url` without any validation. It is common for web servers such as nginx to route requests via the `Host` header, and forward on other request headers. As such as malicious request can be sent with both a `Host` header and an
nvd
CVE-2024-56140P4MEDIUMCVSS 6.5fixed in 4.16.172024-12-18
CVE-2024-56140 [MEDIUM] CWE-352 CVE-2024-56140: Astro is a web framework for content-driven websites. In affected versions a bug in Astro’s CSRF-pro Astro is a web framework for content-driven websites. In affected versions a bug in Astro’s CSRF-protection middleware allows requests to bypass CSRF checks. When the `security.checkOrigin` configuration option is set to `true`, Astro middleware will perform a CSRF check. However, a vulnerability exists that can bypass this security. A semicolon-del
nvd
CVE-2026-33769P4MEDIUMCVSS 5.3v>= 2.10.10, < 5.18.12026-03-24
CVE-2026-33769 [MEDIUM] CWE-20 CVE-2026-33769: Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path enforcement for remote URLs used by server-side fetchers such as the image optimization endpoint. The path matching logic for /* wildcards is unanchored, so a pathname that contains the allowed prefix later in the path can still ma
nvd
CVE-2026-73422P4MEDIUMCVSS 5.3v>= 2.9.0, < 7.1.02026-08-12
CVE-2026-73422 [MEDIUM] CWE-79 CVE-2026-73422: Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side Vi Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS generator interpolates animation properties into an inline style element without escaping them for CSS and HTML contexts. An attacker-controlled View Transition animation value such as duration can terminate the generated style elemen
nvd
CVE-2025-64765P4MEDIUMCVSS 5.3fixed in 5.15.82025-11-19
CVE-2025-64765 [MEDIUM] CWE-22 CVE-2025-64765: Astro is a web framework. Prior to version 5.15.8, a mismatch exists between how Astro normalizes re Astro is a web framework. Prior to version 5.15.8, a mismatch exists between how Astro normalizes request paths for routing/rendering and how the application’s middleware reads the path for validation checks. Astro internally applies decodeURI() to determine which route to render, while the middleware uses context.url.pathname without applying the sa
nvd
Withastro Astro vulnerabilities | cvebase