astro records
26 published records for vendor astro.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-20 Improper Input Validation2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)2
The weakness classes this vendor ships most often: where to look.
CWEAll records
26 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2026-33768No exploit | Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`astro · \@astrojs\/vercel · CWE-441 | Critical9.1 | — | 0.5% | Mar 24, 2026 |
31Monitor | CVE-2024-56159Proof of concept | Server source code is exposed to the public if sourcemaps are enabledastro · astro · CWE-219 | High7.8 | — | 1.5% | Dec 19, 2024 |
30Monitor | CVE-2026-27729No exploit | Astro has memory exhaustion DoS due to missing request body size limit in Server Actionsastro · \@astrojs\/node · CWE-770 | High7.5 | — | 0.8% | Feb 23, 2026 |
30Monitor | CVE-2026-29772No exploit | Astro: Memory exhaustion DoS due to missing request body size limit in Server Islandsastro · \@astrojs\/node · CWE-770 | High7.5 | — | 0.4% | Mar 24, 2026 |
30Monitor | CVE-2026-54299No exploit | Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)astro · astro · CWE-20 | High7.5 | — | 0.3% | Jun 22, 2026 |
28Monitor | CVE-2026-25545Proof of concept | Astro has Full-Read SSRF in error rendering via Host: header injectionastro · \@astrojs\/node · CWE-918 | Medium6.9 | — | 1.9% | Feb 23, 2026 |
28Monitor | CVE-2026-27829No exploit | Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSizeastro · \@astrojs\/node · CWE-918 | High7.2 | — | 0.4% | Feb 25, 2026 |
28Monitor | CVE-2025-59837No exploit | astro allows bypass of image proxy domain validation leading to SSRF and potential XSSastro · astro · CWE-79 | High7.2 | — | 0.4% | Oct 28, 2025 |
27Monitor | CVE-2025-55303Proof of concept | Unauthorized third-party images in Astro’s _image endpointastro · astro · CWE-79 | Medium6.9 | — | 0.6% | Aug 19, 2025 |
27Monitor | CVE-2025-64765No exploit | Astro middleware authentication checks based on url.pathname can be bypassed via url encoded valuesastro · astro · CWE-22 | Medium6.9 | — | 0.5% | Nov 19, 2025 |
26Monitor | CVE-2025-64525Proof of concept | Astro: URL manipulation via unsanitized headers leads to path-based middleware protections bypass, potential SSRF/cache-poisoning, CVE-2025-61925 bypassastro · astro · CWE-918 | Medium6.5 | — | 1.2% | Nov 13, 2025 |
26Monitor | CVE-2025-58179Proof of concept | Astro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpointastro · \@astrojs\/cloudflare · CWE-918 | Medium6.5 | — | 0.8% | Sep 4, 2025 |
26Monitor | CVE-2025-61925No exploit | Astro's `X-Forwarded-Host` is reflected with no validationastro · astro · CWE-470 | Medium6.5 | — | 0.4% | Oct 10, 2025 |
26Monitor | CVE-2025-66202No exploit | Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765astro · astro · CWE-647 | Medium6.5 | — | 0.3% | Dec 8, 2025 |
26Monitor | CVE-2024-56140No exploit | Bypass of CSRF Middleware in Astroastro · astro · CWE-352 | Medium6.5 | — | 0.2% | Dec 18, 2024 |
24Monitor | CVE-2026-41067No exploit | Astro: XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypassastro · astro · CWE-79 | Medium6.1 | — | 0.3% | Apr 24, 2026 |
24Monitor | CVE-2026-50146No exploit | Astro: Reflected XSS via unescaped slot nameastro · astro · CWE-80 | Medium6.1 | — | 0.3% | Jun 22, 2026 |
24Monitor | CVE-2025-65019No exploit | Astro Cloudflare adapter has a Stored Cross Site Scripting vulnerability in /_image endpointastro · astro · CWE-79 | Medium6.1 | — | 0.3% | Nov 19, 2025 |
24Monitor | CVE-2025-64745No exploit | Astro development server error page vulnerable to reflected Cross-site Scriptingastro · astro · CWE-79 | Medium6.1 | — | 0.2% | Nov 13, 2025 |
24Monitor | CVE-2026-54298No exploit | Astro: XSS via Unescaped Attribute Names in Spread Propsastro · astro · CWE-79 | Medium6.1 | — | 0.2% | Jun 22, 2026 |
22Monitor | CVE-2025-54793Proof of concept | Astro: Duplicate trailing slash feature can lead to Open Redirectsastro · astro · CWE-601 | Medium5.5 | — | 0.6% | Aug 7, 2025 |
21Monitor | CVE-2025-64764Proof of concept | Astro is vulnerable to Reflected XSS via the server islands featureastro · astro · CWE-80 | Medium5.4 | — | 0.5% | Nov 19, 2025 |
21Monitor | CVE-2024-47885No exploit | astro's client-side router has DOM Clobbering Gadget that leads to XSSastro · astro · CWE-79 | Medium5.4 | — | 0.4% | Oct 14, 2024 |
14Monitor | CVE-2025-64757No exploit | Astro Development Server is Vulnerable to Arbitrary Local File Readastro · astro · CWE-22 | Low3.5 | — | 0.4% | Nov 19, 2025 |
11Monitor | CVE-2026-33769No exploit | Astro: Remote allowlist bypass via unanchored matchPathname wildcardastro · astro · CWE-20 | Low2.9 | — | 0.4% | Mar 24, 2026 |
- CVE-2026-3376836Monitor
Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`
CriticalCVSS 9.1No exploitEPSS 0%astro · \@astrojs\/vercelMar 24, 2026
- CVE-2024-5615931Monitor
Server source code is exposed to the public if sourcemaps are enabled
HighCVSS 7.8Proof of conceptEPSS 2%astro · astroDec 19, 2024
- CVE-2026-2772930Monitor
Astro has memory exhaustion DoS due to missing request body size limit in Server Actions
HighCVSS 7.5No exploitEPSS 1%astro · \@astrojs\/nodeFeb 23, 2026
- CVE-2026-2977230Monitor
Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands
HighCVSS 7.5No exploitEPSS 0%astro · \@astrojs\/nodeMar 24, 2026
- CVE-2026-5429930Monitor
Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)
HighCVSS 7.5No exploitEPSS 0%astro · astroJun 22, 2026
- CVE-2026-2554528Monitor
Astro has Full-Read SSRF in error rendering via Host: header injection
MediumCVSS 6.9Proof of conceptEPSS 2%astro · \@astrojs\/nodeFeb 23, 2026
- CVE-2026-2782928Monitor
Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize
HighCVSS 7.2No exploitEPSS 0%astro · \@astrojs\/nodeFeb 25, 2026
- CVE-2025-5983728Monitor
astro allows bypass of image proxy domain validation leading to SSRF and potential XSS
HighCVSS 7.2No exploitEPSS 0%astro · astroOct 28, 2025
- CVE-2025-5530327Monitor
Unauthorized third-party images in Astro’s _image endpoint
MediumCVSS 6.9Proof of conceptEPSS 1%astro · astroAug 19, 2025
- CVE-2025-6476527Monitor
Astro middleware authentication checks based on url.pathname can be bypassed via url encoded values
MediumCVSS 6.9No exploitEPSS 1%astro · astroNov 19, 2025
- CVE-2025-6452526Monitor
Astro: URL manipulation via unsanitized headers leads to path-based middleware protections bypass, potential SSRF/cache-poisoning, CVE-2025-61925 bypass
MediumCVSS 6.5Proof of conceptEPSS 1%astro · astroNov 13, 2025
- CVE-2025-5817926Monitor
Astro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpoint
MediumCVSS 6.5Proof of conceptEPSS 1%astro · \@astrojs\/cloudflareSep 4, 2025
- CVE-2025-6192526Monitor
Astro's `X-Forwarded-Host` is reflected with no validation
MediumCVSS 6.5No exploitEPSS 0%astro · astroOct 10, 2025
- CVE-2025-6620226Monitor
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
MediumCVSS 6.5No exploitEPSS 0%astro · astroDec 8, 2025
- CVE-2024-5614026Monitor
Bypass of CSRF Middleware in Astro
MediumCVSS 6.5No exploitEPSS 0%astro · astroDec 18, 2024
- CVE-2026-4106724Monitor
Astro: XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypass
MediumCVSS 6.1No exploitEPSS 0%astro · astroApr 24, 2026
- CVE-2026-5014624Monitor
Astro: Reflected XSS via unescaped slot name
MediumCVSS 6.1No exploitEPSS 0%astro · astroJun 22, 2026
- CVE-2025-6501924Monitor
Astro Cloudflare adapter has a Stored Cross Site Scripting vulnerability in /_image endpoint
MediumCVSS 6.1No exploitEPSS 0%astro · astroNov 19, 2025
- CVE-2025-6474524Monitor
Astro development server error page vulnerable to reflected Cross-site Scripting
MediumCVSS 6.1No exploitEPSS 0%astro · astroNov 13, 2025
- CVE-2026-5429824Monitor
Astro: XSS via Unescaped Attribute Names in Spread Props
MediumCVSS 6.1No exploitEPSS 0%astro · astroJun 22, 2026
- CVE-2025-5479322Monitor
Astro: Duplicate trailing slash feature can lead to Open Redirects
MediumCVSS 5.5Proof of conceptEPSS 1%astro · astroAug 7, 2025
- CVE-2025-6476421Monitor
Astro is vulnerable to Reflected XSS via the server islands feature
MediumCVSS 5.4Proof of conceptEPSS 0%astro · astroNov 19, 2025
- CVE-2024-4788521Monitor
astro's client-side router has DOM Clobbering Gadget that leads to XSS
MediumCVSS 5.4No exploitEPSS 0%astro · astroOct 14, 2024
- CVE-2025-6475714Monitor
Astro Development Server is Vulnerable to Arbitrary Local File Read
LowCVSS 3.5No exploitEPSS 0%astro · astroNov 19, 2025
- CVE-2026-3376911Monitor
Astro: Remote allowlist bypass via unanchored matchPathname wildcard
LowCVSS 2.9No exploitEPSS 0%astro · astroMar 24, 2026