Astro before 5.17.3 and @astrojs/node before 9.5.4 are vulnerable to full-read SSRF due to improper Host header validation in error page rendering, allowing attackers to redirect requests and access internal resources.
id: CVE-2026-25545
info:
name: Astro SSR - Server-Side Request Forgery
author: ritikchaddha
s
...