📦 Astro

by Astro

🔍 What is Astro?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-64764

HIGH CVSS 7.1 Nov 19, 2025

A reflected cross-site scripting (XSS) vulnerability exists in Astro web framework when using server islands feature. Attackers can inject malicious scripts that execute in users' browsers when they v...

CVE-2025-59837

HIGH CVSS 7.2 Oct 28, 2025

This vulnerability in Astro's image proxy allows attackers to bypass domain validation by using backslashes in the href parameter, enabling server-side requests to arbitrary URLs. This can lead to SSR...

CVE-2025-66202

MEDIUM CVSS 6.5 Dec 9, 2025

This vulnerability allows unauthenticated attackers to bypass path-based authentication checks in Astro web framework middleware by using double-encoded URLs. Attackers can access protected routes tha...

CVE-2025-65019

MEDIUM CVSS 5.4 Nov 19, 2025

This vulnerability in Astro's Cloudflare adapter allows attackers to inject malicious SVG payloads via data: URLs in the image optimization endpoint, enabling Cross-Site Scripting (XSS) attacks. It af...

CVE-2025-64765

MEDIUM CVSS 5.3 Nov 19, 2025

This vulnerability allows attackers to bypass middleware validation checks in Astro web applications by using URL-encoded path variants. The mismatch between how Astro normalizes paths for routing ver...

CVE-2025-64525

MEDIUM CVSS 6.5 Nov 13, 2025

Astro web framework versions 2.16.0 to 5.15.4 with on-demand rendering are vulnerable to header injection attacks. Attackers can manipulate x-forwarded-proto and x-forwarded-port headers to bypass mid...

CVE-2025-61925

MEDIUM CVSS 6.5 Oct 10, 2025

Astro web framework versions before 5.14.2 reflect unvalidated X-Forwarded-Host header values in Astro.url output, allowing attackers to manipulate URLs used for canonical links, login forms, or other...

CVE-2025-55303

MEDIUM CVSS 6.1 Aug 19, 2025

This vulnerability in Astro web framework allows attackers to bypass third-party domain restrictions in the image optimization endpoint. By using protocol-relative URLs (e.g., //example.com/image.png)...

CVE-2025-54793

MEDIUM CVSS 6.1 Aug 8, 2025

Astro web framework versions 5.2.0 through 5.12.7 contain an open redirect vulnerability in trailing slash redirection logic when handling paths with double slashes. Attackers can craft URLs to redire...

CVE-2024-56159

MEDIUM CVSS 5.3 Dec 19, 2024

A vulnerability in Astro web framework's build process exposes server source code via publicly accessible sourcemap files. Unauthenticated attackers can read server-side code, potentially revealing im...

CVE-2024-56140

MEDIUM CVSS 5.9 Dec 18, 2024

This vulnerability allows attackers to bypass CSRF protection in Astro web framework by manipulating Content-Type headers. Websites using Astro with security.checkOrigin enabled are affected. Attacker...

CVE-2025-64757

LOW CVSS 3.5 Nov 19, 2025

A vulnerability in Astro framework's development server allows attackers to read arbitrary local image files through the image optimization endpoint. This affects Astro development environments runnin...