Записи astro
26 опубликованных записей вендора astro.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-20 Improper Input Validation2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
26 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2026-33768Эксплойта нет | Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`astro · \@astrojs\/vercel · CWE-441 | Критическая9,1 | — | 0,5 % | 24 мар. 2026 г. |
31Наблюдать | CVE-2024-56159Proof of concept | Server source code is exposed to the public if sourcemaps are enabledastro · astro · CWE-219 | Высокая7,8 | — | 1,5 % | 19 дек. 2024 г. |
30Наблюдать | CVE-2026-27729Эксплойта нет | Astro has memory exhaustion DoS due to missing request body size limit in Server Actionsastro · \@astrojs\/node · CWE-770 | Высокая7,5 | — | 0,8 % | 23 февр. 2026 г. |
30Наблюдать | CVE-2026-29772Эксплойта нет | Astro: Memory exhaustion DoS due to missing request body size limit in Server Islandsastro · \@astrojs\/node · CWE-770 | Высокая7,5 | — | 0,4 % | 24 мар. 2026 г. |
30Наблюдать | CVE-2026-54299Эксплойта нет | Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)astro · astro · CWE-20 | Высокая7,5 | — | 0,3 % | 22 июн. 2026 г. |
28Наблюдать | CVE-2026-25545Proof of concept | Astro has Full-Read SSRF in error rendering via Host: header injectionastro · \@astrojs\/node · CWE-918 | Средняя6,9 | — | 1,9 % | 23 февр. 2026 г. |
28Наблюдать | CVE-2026-27829Эксплойта нет | Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSizeastro · \@astrojs\/node · CWE-918 | Высокая7,2 | — | 0,4 % | 25 февр. 2026 г. |
28Наблюдать | CVE-2025-59837Эксплойта нет | astro allows bypass of image proxy domain validation leading to SSRF and potential XSSastro · astro · CWE-79 | Высокая7,2 | — | 0,4 % | 28 окт. 2025 г. |
27Наблюдать | CVE-2025-55303Proof of concept | Unauthorized third-party images in Astro’s _image endpointastro · astro · CWE-79 | Средняя6,9 | — | 0,6 % | 19 авг. 2025 г. |
27Наблюдать | CVE-2025-64765Эксплойта нет | Astro middleware authentication checks based on url.pathname can be bypassed via url encoded valuesastro · astro · CWE-22 | Средняя6,9 | — | 0,5 % | 19 нояб. 2025 г. |
26Наблюдать | CVE-2025-64525Proof of concept | Astro: URL manipulation via unsanitized headers leads to path-based middleware protections bypass, potential SSRF/cache-poisoning, CVE-2025-61925 bypassastro · astro · CWE-918 | Средняя6,5 | — | 1,2 % | 13 нояб. 2025 г. |
26Наблюдать | CVE-2025-58179Proof of concept | Astro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpointastro · \@astrojs\/cloudflare · CWE-918 | Средняя6,5 | — | 0,8 % | 4 сент. 2025 г. |
26Наблюдать | CVE-2025-61925Эксплойта нет | Astro's `X-Forwarded-Host` is reflected with no validationastro · astro · CWE-470 | Средняя6,5 | — | 0,4 % | 10 окт. 2025 г. |
26Наблюдать | CVE-2025-66202Эксплойта нет | Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765astro · astro · CWE-647 | Средняя6,5 | — | 0,3 % | 9 дек. 2025 г. |
26Наблюдать | CVE-2024-56140Эксплойта нет | Bypass of CSRF Middleware in Astroastro · astro · CWE-352 | Средняя6,5 | — | 0,2 % | 18 дек. 2024 г. |
24Наблюдать | CVE-2026-41067Эксплойта нет | Astro: XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypassastro · astro · CWE-79 | Средняя6,1 | — | 0,3 % | 24 апр. 2026 г. |
24Наблюдать | CVE-2026-50146Эксплойта нет | Astro: Reflected XSS via unescaped slot nameastro · astro · CWE-80 | Средняя6,1 | — | 0,3 % | 22 июн. 2026 г. |
24Наблюдать | CVE-2025-65019Эксплойта нет | Astro Cloudflare adapter has a Stored Cross Site Scripting vulnerability in /_image endpointastro · astro · CWE-79 | Средняя6,1 | — | 0,3 % | 19 нояб. 2025 г. |
24Наблюдать | CVE-2025-64745Эксплойта нет | Astro development server error page vulnerable to reflected Cross-site Scriptingastro · astro · CWE-79 | Средняя6,1 | — | 0,2 % | 13 нояб. 2025 г. |
24Наблюдать | CVE-2026-54298Эксплойта нет | Astro: XSS via Unescaped Attribute Names in Spread Propsastro · astro · CWE-79 | Средняя6,1 | — | 0,2 % | 22 июн. 2026 г. |
22Наблюдать | CVE-2025-54793Proof of concept | Astro: Duplicate trailing slash feature can lead to Open Redirectsastro · astro · CWE-601 | Средняя5,5 | — | 0,6 % | 7 авг. 2025 г. |
21Наблюдать | CVE-2025-64764Proof of concept | Astro is vulnerable to Reflected XSS via the server islands featureastro · astro · CWE-80 | Средняя5,4 | — | 0,5 % | 19 нояб. 2025 г. |
21Наблюдать | CVE-2024-47885Эксплойта нет | astro's client-side router has DOM Clobbering Gadget that leads to XSSastro · astro · CWE-79 | Средняя5,4 | — | 0,4 % | 14 окт. 2024 г. |
14Наблюдать | CVE-2025-64757Эксплойта нет | Astro Development Server is Vulnerable to Arbitrary Local File Readastro · astro · CWE-22 | Низкая3,5 | — | 0,4 % | 19 нояб. 2025 г. |
11Наблюдать | CVE-2026-33769Эксплойта нет | Astro: Remote allowlist bypass via unanchored matchPathname wildcardastro · astro · CWE-20 | Низкая2,9 | — | 0,4 % | 24 мар. 2026 г. |
- CVE-2026-3376836Наблюдать
Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %astro · \@astrojs\/vercel24 мар. 2026 г.
- CVE-2024-5615931Наблюдать
Server source code is exposed to the public if sourcemaps are enabled
ВысокаяCVSS 7,8Proof of conceptEPSS 2 %astro · astro19 дек. 2024 г.
- CVE-2026-2772930Наблюдать
Astro has memory exhaustion DoS due to missing request body size limit in Server Actions
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %astro · \@astrojs\/node23 февр. 2026 г.
- CVE-2026-2977230Наблюдать
Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %astro · \@astrojs\/node24 мар. 2026 г.
- CVE-2026-5429930Наблюдать
Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %astro · astro22 июн. 2026 г.
- CVE-2026-2554528Наблюдать
Astro has Full-Read SSRF in error rendering via Host: header injection
СредняяCVSS 6,9Proof of conceptEPSS 2 %astro · \@astrojs\/node23 февр. 2026 г.
- CVE-2026-2782928Наблюдать
Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %astro · \@astrojs\/node25 февр. 2026 г.
- CVE-2025-5983728Наблюдать
astro allows bypass of image proxy domain validation leading to SSRF and potential XSS
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %astro · astro28 окт. 2025 г.
- CVE-2025-5530327Наблюдать
Unauthorized third-party images in Astro’s _image endpoint
СредняяCVSS 6,9Proof of conceptEPSS 1 %astro · astro19 авг. 2025 г.
- CVE-2025-6476527Наблюдать
Astro middleware authentication checks based on url.pathname can be bypassed via url encoded values
СредняяCVSS 6,9Эксплойта нетEPSS 1 %astro · astro19 нояб. 2025 г.
- CVE-2025-6452526Наблюдать
Astro: URL manipulation via unsanitized headers leads to path-based middleware protections bypass, potential SSRF/cache-poisoning, CVE-2025-61925 bypass
СредняяCVSS 6,5Proof of conceptEPSS 1 %astro · astro13 нояб. 2025 г.
- CVE-2025-5817926Наблюдать
Astro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpoint
СредняяCVSS 6,5Proof of conceptEPSS 1 %astro · \@astrojs\/cloudflare4 сент. 2025 г.
- CVE-2025-6192526Наблюдать
Astro's `X-Forwarded-Host` is reflected with no validation
СредняяCVSS 6,5Эксплойта нетEPSS 0 %astro · astro10 окт. 2025 г.
- CVE-2025-6620226Наблюдать
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
СредняяCVSS 6,5Эксплойта нетEPSS 0 %astro · astro9 дек. 2025 г.
- CVE-2024-5614026Наблюдать
Bypass of CSRF Middleware in Astro
СредняяCVSS 6,5Эксплойта нетEPSS 0 %astro · astro18 дек. 2024 г.
- CVE-2026-4106724Наблюдать
Astro: XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypass
СредняяCVSS 6,1Эксплойта нетEPSS 0 %astro · astro24 апр. 2026 г.
- CVE-2026-5014624Наблюдать
Astro: Reflected XSS via unescaped slot name
СредняяCVSS 6,1Эксплойта нетEPSS 0 %astro · astro22 июн. 2026 г.
- CVE-2025-6501924Наблюдать
Astro Cloudflare adapter has a Stored Cross Site Scripting vulnerability in /_image endpoint
СредняяCVSS 6,1Эксплойта нетEPSS 0 %astro · astro19 нояб. 2025 г.
- CVE-2025-6474524Наблюдать
Astro development server error page vulnerable to reflected Cross-site Scripting
СредняяCVSS 6,1Эксплойта нетEPSS 0 %astro · astro13 нояб. 2025 г.
- CVE-2026-5429824Наблюдать
Astro: XSS via Unescaped Attribute Names in Spread Props
СредняяCVSS 6,1Эксплойта нетEPSS 0 %astro · astro22 июн. 2026 г.
- CVE-2025-5479322Наблюдать
Astro: Duplicate trailing slash feature can lead to Open Redirects
СредняяCVSS 5,5Proof of conceptEPSS 1 %astro · astro7 авг. 2025 г.
- CVE-2025-6476421Наблюдать
Astro is vulnerable to Reflected XSS via the server islands feature
СредняяCVSS 5,4Proof of conceptEPSS 0 %astro · astro19 нояб. 2025 г.
- CVE-2024-4788521Наблюдать
astro's client-side router has DOM Clobbering Gadget that leads to XSS
СредняяCVSS 5,4Эксплойта нетEPSS 0 %astro · astro14 окт. 2024 г.
- CVE-2025-6475714Наблюдать
Astro Development Server is Vulnerable to Arbitrary Local File Read
НизкаяCVSS 3,5Эксплойта нетEPSS 0 %astro · astro19 нояб. 2025 г.
- CVE-2026-3376911Наблюдать
Astro: Remote allowlist bypass via unanchored matchPathname wildcard
НизкаяCVSS 2,9Эксплойта нетEPSS 0 %astro · astro24 мар. 2026 г.