Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

astro — Vulnerabilities & Security Advisories 35

All 35 CVE vulnerabilities found in astro, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the open-source framework Astro, focusing on Common Weakness Enumeration (CWE) types and security tags relevant to its architecture. It collects historical data regarding security vulnerabilities affecting the Astro static site generator, covering the period from the project's early releases through to the most recent stable versions. By providing a consolidated view of past incidents, this resource allows developers and security analysts to track vendor advisories issued by the Astro maintainers, understand the patterns and impacts of specific weakness classes within the framework, and look up the complete vulnerability history of the product to assess its current security posture. The information presented is derived from official changelogs, security updates, and community reports, ensuring that users have a clear timeline of when issues were identified, patched, or disclosed. This aggregate view helps teams evaluate the risk profile of incorporating Astro into their tech stack by highlighting recurring security themes and the responsiveness of the development team to reported flaws. Users can utilize this data to inform their own security audits, dependency management strategies, and upgrade schedules without needing to manually sift through individual release notes or scattered forum discussions.

Vendor: withastro

CVE IDTitleCVSSSeverityPublished
CVE-2026-59730 @astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect CWE-601 2.1 Low2026-07-27
CVE-2026-59728 @astrojs/rss: XML Injection via Unescaped RSS Feed Fields CWE-91 4.3 Medium2026-07-27
CVE-2026-59727 Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands CWE-79 2.1 Low2026-07-27
CVE-2026-59729 Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298) CWE-79 5.1 Medium2026-07-27
CVE-2026-59731 Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch CWE-647 8.2 High2026-07-08
CVE-2026-54299 Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL) CWE-20 7.5 High2026-06-22
CVE-2026-54298 Astro: XSS via Unescaped Attribute Names in Spread Props CWE-79 4.2 Medium2026-06-22
CVE-2026-50146 Astro: Reflected XSS via unescaped slot name CWE-80 7.1 High2026-06-22
CVE-2026-54300 @astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config CWE-918 5.3 Medium2026-06-22
CVE-2026-45028 Astro: Server island encrypted parameters vulnerable to cross-component replay CWE-323--2026-05-13
CVE-2026-41248 Official Clerk JavaScript SDKs: Middleware-based route protection bypass CWE-436 9.1 Critical2026-04-24
CVE-2026-41322 @astrojs/node: Cache Poisoning due to incorrect error handling when if-match header is malformed CWE-525 5.3 Medium2026-04-24
CVE-2026-41067 Astro: XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypass CWE-79 6.1 Medium2026-04-24
CVE-2026-33769 Astro: Remote allowlist bypass via unanchored matchPathname wildcard CWE-20 9.1 -2026-03-24
CVE-2026-33768 Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path` CWE-441 6.5 Medium2026-03-24
CVE-2026-29772 Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands CWE-770 5.9 Medium2026-03-24
CVE-2026-27829 Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize CWE-918 6.5 Medium2026-02-26
CVE-2026-27729 Astro has memory exhaustion DoS due to missing request body size limit in Server Actions CWE-770 5.9 Medium2026-02-24
CVE-2026-25545 Astro has Full-Read SSRF in error rendering via Host: header injection CWE-918 9.1 -2026-02-24
CVE-2025-66202 Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765 CWE-647 6.5 Medium2025-12-08
CVE-2025-64765 Astro middleware authentication checks based on url.pathname can be bypassed via url encoded values CWE-22 8.2AIHighAI2025-11-19
CVE-2025-64764 Astro is vulnerable to Reflected XSS via the server islands feature CWE-80 7.1 High2025-11-19
CVE-2025-65019 Astro Cloudflare adapter has a Stored Cross Site Scripting vulnerability in /_image endpoint CWE-79 5.4 Medium2025-11-19
CVE-2025-64757 Astro Development Server is Vulnerable to Arbitrary Local File Read CWE-22 3.5 Low2025-11-19
CVE-2025-64745 Astro development server error page vulnerable to reflected Cross-site Scripting CWE-79 2.7 Low2025-11-13
CVE-2025-64525 Astro: URL manipulation via unsanitized headers leads to path-based middleware protections bypass, potential SSRF/cache-poisoning, CVE-2025-61925 bypass CWE-918 6.5 Medium2025-11-13
CVE-2025-59837 astro allows bypass of image proxy domain validation leading to SSRF and potential XSS CWE-918 7.2 High2025-10-28
CVE-2025-61925 Astro's `X-Forwarded-Host` is reflected with no validation CWE-470 6.5 Medium2025-10-10
CVE-2025-58179 Astro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpoint CWE-918 7.2 High2025-09-04
CVE-2025-55303 Unauthorized third-party images in Astro’s _image endpoint CWE-79 7.2AIHighAI2025-08-19

All 35 known CVE vulnerabilities affecting astro with full Chinese analysis, references, and POCs where available.