vciy

CVEs we hold for Withastro

Records whose assigning authority named Withastro as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-84376Astro: Authorization bypass from missing path-segment boundary check when stripping the configured basewithastro astro
CVE-2026-73425@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters…withastro astro
CVE-2026-73424Astro: Unauthenticated path override in the @astrojs/vercel ISR functionwithastro astro
CVE-2026-73423Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misorderedwithastro astro
CVE-2026-73422Astro: Reflected XSS via unescaped View Transition animation propertieswithastro astro
CVE-2026-59731Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatchwithastro astro
CVE-2026-59730@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirectwithastro astro
CVE-2026-59729Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)withastro astro
CVE-2026-59728@astrojs/rss: XML Injection via Unescaped RSS Feed Fieldswithastro astro
CVE-2026-59727Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islandswithastro astro
CVE-2026-54300@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN configwithastro astro
CVE-2026-54299Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated…withastro astro
CVE-2026-54298Astro: XSS via Unescaped Attribute Names in Spread Propswithastro astro
CVE-2026-50146Astro: Reflected XSS via unescaped slot namewithastro astro
CVE-2026-45028Astro: Server island encrypted parameters vulnerable to cross-component replaywithastro astro
CVE-2026-41322@astrojs/node: Cache Poisoning due to incorrect error handling when if-match header is malformedwithastro astro
CVE-2026-41321@astrojs/cloudflare: SSRF via redirect following in Cloudflare image-binding-transform endpointwithastro @astrojs/cloudflare
CVE-2026-41067Astro: XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypasswithastro astro
CVE-2026-33769Astro: Remote allowlist bypass via unanchored matchPathname wildcardwithastro astro
CVE-2026-33768Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`withastro astro
CVE-2026-29772Astro: Memory exhaustion DoS due to missing request body size limit in Server Islandswithastro astro
CVE-2026-27829Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSizewithastro astro
CVE-2026-27729Astro has memory exhaustion DoS due to missing request body size limit in Server Actionswithastro astro
CVE-2026-25545Astro has Full-Read SSRF in error rendering via Host: header injectionwithastro astro
CVE-2025-66202Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765withastro astro
CVE-2025-65019Astro Cloudflare adapter has a Stored Cross Site Scripting vulnerability in /_image endpointwithastro astro
CVE-2025-64765Astro middleware authentication checks based on url.pathname can be bypassed via url encoded valueswithastro astro
CVE-2025-64764Astro is vulnerable to Reflected XSS via the server islands featurewithastro astro
CVE-2025-64757Astro Development Server is Vulnerable to Arbitrary Local File Readwithastro astro
CVE-2025-64745Astro development server error page vulnerable to reflected Cross-site Scriptingwithastro astro
CVE-2025-64525Astro: URL manipulation via unsanitized headers leads to path-based middleware protections bypass, potential…withastro astro
CVE-2025-61925Astro's `X-Forwarded-Host` is reflected with no validationwithastro astro
CVE-2025-59837astro allows bypass of image proxy domain validation leading to SSRF and potential XSSwithastro astro
CVE-2025-58179Astro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpointwithastro astro
CVE-2025-55303Unauthorized third-party images in Astro’s _image endpointwithastro astro
CVE-2025-55207@astrojs/node's trailing slash handling causes open redirect issuewithastro astro
CVE-2025-54793Astro: Duplicate trailing slash feature can lead to Open Redirectswithastro astro
CVE-2024-56159Server source code is exposed to the public if sourcemaps are enabledwithastro astro
CVE-2024-56140Bypass of CSRF Middleware in Astrowithastro astro
CVE-2024-47885astro's client-side router has DOM Clobbering Gadget that leads to XSSwithastro astro

40 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.