Skip to content
Noroxi

astro records

26 published records for vendor astro.

All records

26 records
  • Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`

    CriticalCVSS 9.1No exploitEPSS 0%

    astro · \@astrojs\/vercelMar 24, 2026

  • Server source code is exposed to the public if sourcemaps are enabled

    HighCVSS 7.8Proof of conceptEPSS 2%

    astro · astroDec 19, 2024

  • Astro has memory exhaustion DoS due to missing request body size limit in Server Actions

    HighCVSS 7.5No exploitEPSS 1%

    astro · \@astrojs\/nodeFeb 23, 2026

  • Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands

    HighCVSS 7.5No exploitEPSS 0%

    astro · \@astrojs\/nodeMar 24, 2026

  • Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)

    HighCVSS 7.5No exploitEPSS 0%

    astro · astroJun 22, 2026

  • Astro has Full-Read SSRF in error rendering via Host: header injection

    MediumCVSS 6.9Proof of conceptEPSS 2%

    astro · \@astrojs\/nodeFeb 23, 2026

  • Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize

    HighCVSS 7.2No exploitEPSS 0%

    astro · \@astrojs\/nodeFeb 25, 2026

  • astro allows bypass of image proxy domain validation leading to SSRF and potential XSS

    HighCVSS 7.2No exploitEPSS 0%

    astro · astroOct 28, 2025

  • Unauthorized third-party images in Astro’s _image endpoint

    MediumCVSS 6.9Proof of conceptEPSS 1%

    astro · astroAug 19, 2025

  • Astro middleware authentication checks based on url.pathname can be bypassed via url encoded values

    MediumCVSS 6.9No exploitEPSS 1%

    astro · astroNov 19, 2025

  • Astro: URL manipulation via unsanitized headers leads to path-based middleware protections bypass, potential SSRF/cache-poisoning, CVE-2025-61925 bypass

    MediumCVSS 6.5Proof of conceptEPSS 1%

    astro · astroNov 13, 2025

  • Astro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpoint

    MediumCVSS 6.5Proof of conceptEPSS 1%

    astro · \@astrojs\/cloudflareSep 4, 2025

  • Astro's `X-Forwarded-Host` is reflected with no validation

    MediumCVSS 6.5No exploitEPSS 0%

    astro · astroOct 10, 2025

  • Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765

    MediumCVSS 6.5No exploitEPSS 0%

    astro · astroDec 8, 2025

  • Bypass of CSRF Middleware in Astro

    MediumCVSS 6.5No exploitEPSS 0%

    astro · astroDec 18, 2024

  • Astro: XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypass

    MediumCVSS 6.1No exploitEPSS 0%

    astro · astroApr 24, 2026

  • Astro: Reflected XSS via unescaped slot name

    MediumCVSS 6.1No exploitEPSS 0%

    astro · astroJun 22, 2026

  • Astro Cloudflare adapter has a Stored Cross Site Scripting vulnerability in /_image endpoint

    MediumCVSS 6.1No exploitEPSS 0%

    astro · astroNov 19, 2025

  • Astro development server error page vulnerable to reflected Cross-site Scripting

    MediumCVSS 6.1No exploitEPSS 0%

    astro · astroNov 13, 2025

  • Astro: XSS via Unescaped Attribute Names in Spread Props

    MediumCVSS 6.1No exploitEPSS 0%

    astro · astroJun 22, 2026

  • Astro: Duplicate trailing slash feature can lead to Open Redirects

    MediumCVSS 5.5Proof of conceptEPSS 1%

    astro · astroAug 7, 2025

  • Astro is vulnerable to Reflected XSS via the server islands feature

    MediumCVSS 5.4Proof of conceptEPSS 0%

    astro · astroNov 19, 2025

  • astro's client-side router has DOM Clobbering Gadget that leads to XSS

    MediumCVSS 5.4No exploitEPSS 0%

    astro · astroOct 14, 2024

  • Astro Development Server is Vulnerable to Arbitrary Local File Read

    LowCVSS 3.5No exploitEPSS 0%

    astro · astroNov 19, 2025

  • Astro: Remote allowlist bypass via unanchored matchPathname wildcard

    LowCVSS 2.9No exploitEPSS 0%

    astro · astroMar 24, 2026