astro kayıtları
astro üreticisine ait 26 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-20 Improper Input Validation2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
26 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2026-33768İstismar yok | Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`astro · \@astrojs\/vercel · CWE-441 | Kritik9,1 | — | %0,5 | 24 Mar 2026 |
31İzleyin | CVE-2024-56159Kavram kanıtı | Server source code is exposed to the public if sourcemaps are enabledastro · astro · CWE-219 | Yüksek7,8 | — | %1,5 | 19 Ara 2024 |
30İzleyin | CVE-2026-27729İstismar yok | Astro has memory exhaustion DoS due to missing request body size limit in Server Actionsastro · \@astrojs\/node · CWE-770 | Yüksek7,5 | — | %0,8 | 23 Şub 2026 |
30İzleyin | CVE-2026-29772İstismar yok | Astro: Memory exhaustion DoS due to missing request body size limit in Server Islandsastro · \@astrojs\/node · CWE-770 | Yüksek7,5 | — | %0,4 | 24 Mar 2026 |
30İzleyin | CVE-2026-54299İstismar yok | Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)astro · astro · CWE-20 | Yüksek7,5 | — | %0,3 | 22 Haz 2026 |
28İzleyin | CVE-2026-25545Kavram kanıtı | Astro has Full-Read SSRF in error rendering via Host: header injectionastro · \@astrojs\/node · CWE-918 | Orta6,9 | — | %1,9 | 23 Şub 2026 |
28İzleyin | CVE-2026-27829İstismar yok | Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSizeastro · \@astrojs\/node · CWE-918 | Yüksek7,2 | — | %0,4 | 25 Şub 2026 |
28İzleyin | CVE-2025-59837İstismar yok | astro allows bypass of image proxy domain validation leading to SSRF and potential XSSastro · astro · CWE-79 | Yüksek7,2 | — | %0,4 | 28 Eki 2025 |
27İzleyin | CVE-2025-55303Kavram kanıtı | Unauthorized third-party images in Astro’s _image endpointastro · astro · CWE-79 | Orta6,9 | — | %0,6 | 19 Ağu 2025 |
27İzleyin | CVE-2025-64765İstismar yok | Astro middleware authentication checks based on url.pathname can be bypassed via url encoded valuesastro · astro · CWE-22 | Orta6,9 | — | %0,5 | 19 Kas 2025 |
26İzleyin | CVE-2025-64525Kavram kanıtı | Astro: URL manipulation via unsanitized headers leads to path-based middleware protections bypass, potential SSRF/cache-poisoning, CVE-2025-61925 bypassastro · astro · CWE-918 | Orta6,5 | — | %1,2 | 13 Kas 2025 |
26İzleyin | CVE-2025-58179Kavram kanıtı | Astro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpointastro · \@astrojs\/cloudflare · CWE-918 | Orta6,5 | — | %0,8 | 4 Eyl 2025 |
26İzleyin | CVE-2025-61925İstismar yok | Astro's `X-Forwarded-Host` is reflected with no validationastro · astro · CWE-470 | Orta6,5 | — | %0,4 | 10 Eki 2025 |
26İzleyin | CVE-2025-66202İstismar yok | Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765astro · astro · CWE-647 | Orta6,5 | — | %0,3 | 8 Ara 2025 |
26İzleyin | CVE-2024-56140İstismar yok | Bypass of CSRF Middleware in Astroastro · astro · CWE-352 | Orta6,5 | — | %0,2 | 18 Ara 2024 |
24İzleyin | CVE-2026-41067İstismar yok | Astro: XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypassastro · astro · CWE-79 | Orta6,1 | — | %0,3 | 24 Nis 2026 |
24İzleyin | CVE-2026-50146İstismar yok | Astro: Reflected XSS via unescaped slot nameastro · astro · CWE-80 | Orta6,1 | — | %0,3 | 22 Haz 2026 |
24İzleyin | CVE-2025-65019İstismar yok | Astro Cloudflare adapter has a Stored Cross Site Scripting vulnerability in /_image endpointastro · astro · CWE-79 | Orta6,1 | — | %0,3 | 19 Kas 2025 |
24İzleyin | CVE-2025-64745İstismar yok | Astro development server error page vulnerable to reflected Cross-site Scriptingastro · astro · CWE-79 | Orta6,1 | — | %0,2 | 13 Kas 2025 |
24İzleyin | CVE-2026-54298İstismar yok | Astro: XSS via Unescaped Attribute Names in Spread Propsastro · astro · CWE-79 | Orta6,1 | — | %0,2 | 22 Haz 2026 |
22İzleyin | CVE-2025-54793Kavram kanıtı | Astro: Duplicate trailing slash feature can lead to Open Redirectsastro · astro · CWE-601 | Orta5,5 | — | %0,6 | 7 Ağu 2025 |
21İzleyin | CVE-2025-64764Kavram kanıtı | Astro is vulnerable to Reflected XSS via the server islands featureastro · astro · CWE-80 | Orta5,4 | — | %0,5 | 19 Kas 2025 |
21İzleyin | CVE-2024-47885İstismar yok | astro's client-side router has DOM Clobbering Gadget that leads to XSSastro · astro · CWE-79 | Orta5,4 | — | %0,4 | 14 Eki 2024 |
14İzleyin | CVE-2025-64757İstismar yok | Astro Development Server is Vulnerable to Arbitrary Local File Readastro · astro · CWE-22 | Düşük3,5 | — | %0,4 | 19 Kas 2025 |
11İzleyin | CVE-2026-33769İstismar yok | Astro: Remote allowlist bypass via unanchored matchPathname wildcardastro · astro · CWE-20 | Düşük2,9 | — | %0,4 | 24 Mar 2026 |
- CVE-2026-3376836İzleyin
Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`
KritikCVSS 9,1İstismar yokEPSS %0astro · \@astrojs\/vercel24 Mar 2026
- CVE-2024-5615931İzleyin
Server source code is exposed to the public if sourcemaps are enabled
YüksekCVSS 7,8Kavram kanıtıEPSS %2astro · astro19 Ara 2024
- CVE-2026-2772930İzleyin
Astro has memory exhaustion DoS due to missing request body size limit in Server Actions
YüksekCVSS 7,5İstismar yokEPSS %1astro · \@astrojs\/node23 Şub 2026
- CVE-2026-2977230İzleyin
Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands
YüksekCVSS 7,5İstismar yokEPSS %0astro · \@astrojs\/node24 Mar 2026
- CVE-2026-5429930İzleyin
Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)
YüksekCVSS 7,5İstismar yokEPSS %0astro · astro22 Haz 2026
- CVE-2026-2554528İzleyin
Astro has Full-Read SSRF in error rendering via Host: header injection
OrtaCVSS 6,9Kavram kanıtıEPSS %2astro · \@astrojs\/node23 Şub 2026
- CVE-2026-2782928İzleyin
Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize
YüksekCVSS 7,2İstismar yokEPSS %0astro · \@astrojs\/node25 Şub 2026
- CVE-2025-5983728İzleyin
astro allows bypass of image proxy domain validation leading to SSRF and potential XSS
YüksekCVSS 7,2İstismar yokEPSS %0astro · astro28 Eki 2025
- CVE-2025-5530327İzleyin
Unauthorized third-party images in Astro’s _image endpoint
OrtaCVSS 6,9Kavram kanıtıEPSS %1astro · astro19 Ağu 2025
- CVE-2025-6476527İzleyin
Astro middleware authentication checks based on url.pathname can be bypassed via url encoded values
OrtaCVSS 6,9İstismar yokEPSS %1astro · astro19 Kas 2025
- CVE-2025-6452526İzleyin
Astro: URL manipulation via unsanitized headers leads to path-based middleware protections bypass, potential SSRF/cache-poisoning, CVE-2025-61925 bypass
OrtaCVSS 6,5Kavram kanıtıEPSS %1astro · astro13 Kas 2025
- CVE-2025-5817926İzleyin
Astro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpoint
OrtaCVSS 6,5Kavram kanıtıEPSS %1astro · \@astrojs\/cloudflare4 Eyl 2025
- CVE-2025-6192526İzleyin
Astro's `X-Forwarded-Host` is reflected with no validation
OrtaCVSS 6,5İstismar yokEPSS %0astro · astro10 Eki 2025
- CVE-2025-6620226İzleyin
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
OrtaCVSS 6,5İstismar yokEPSS %0astro · astro8 Ara 2025
- CVE-2024-5614026İzleyin
Bypass of CSRF Middleware in Astro
OrtaCVSS 6,5İstismar yokEPSS %0astro · astro18 Ara 2024
- CVE-2026-4106724İzleyin
Astro: XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypass
OrtaCVSS 6,1İstismar yokEPSS %0astro · astro24 Nis 2026
- CVE-2026-5014624İzleyin
Astro: Reflected XSS via unescaped slot name
OrtaCVSS 6,1İstismar yokEPSS %0astro · astro22 Haz 2026
- CVE-2025-6501924İzleyin
Astro Cloudflare adapter has a Stored Cross Site Scripting vulnerability in /_image endpoint
OrtaCVSS 6,1İstismar yokEPSS %0astro · astro19 Kas 2025
- CVE-2025-6474524İzleyin
Astro development server error page vulnerable to reflected Cross-site Scripting
OrtaCVSS 6,1İstismar yokEPSS %0astro · astro13 Kas 2025
- CVE-2026-5429824İzleyin
Astro: XSS via Unescaped Attribute Names in Spread Props
OrtaCVSS 6,1İstismar yokEPSS %0astro · astro22 Haz 2026
- CVE-2025-5479322İzleyin
Astro: Duplicate trailing slash feature can lead to Open Redirects
OrtaCVSS 5,5Kavram kanıtıEPSS %1astro · astro7 Ağu 2025
- CVE-2025-6476421İzleyin
Astro is vulnerable to Reflected XSS via the server islands feature
OrtaCVSS 5,4Kavram kanıtıEPSS %0astro · astro19 Kas 2025
- CVE-2024-4788521İzleyin
astro's client-side router has DOM Clobbering Gadget that leads to XSS
OrtaCVSS 5,4İstismar yokEPSS %0astro · astro14 Eki 2024
- CVE-2025-6475714İzleyin
Astro Development Server is Vulnerable to Arbitrary Local File Read
DüşükCVSS 3,5İstismar yokEPSS %0astro · astro19 Kas 2025
- CVE-2026-3376911İzleyin
Astro: Remote allowlist bypass via unanchored matchPathname wildcard
DüşükCVSS 2,9İstismar yokEPSS %0astro · astro24 Mar 2026