CVEs we hold for Withastro
Records whose assigning authority named Withastro as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-84376Astro: Authorization bypass from missing path-segment boundary check when stripping the configured basewithastro astro
CVE-2026-73425@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters…withastro astro
CVE-2026-73424Astro: Unauthenticated path override in the @astrojs/vercel ISR functionwithastro astro
CVE-2026-73423Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misorderedwithastro astro
CVE-2026-73422Astro: Reflected XSS via unescaped View Transition animation propertieswithastro astro
CVE-2026-59731Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatchwithastro astro
CVE-2026-59730@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirectwithastro astro
CVE-2026-59729Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)withastro astro
CVE-2026-59727Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islandswithastro astro
CVE-2026-54300@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN configwithastro astro
CVE-2026-54299Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated…withastro astro
CVE-2026-45028Astro: Server island encrypted parameters vulnerable to cross-component replaywithastro astro
CVE-2026-41322@astrojs/node: Cache Poisoning due to incorrect error handling when if-match header is malformedwithastro astro
CVE-2026-41321@astrojs/cloudflare: SSRF via redirect following in Cloudflare image-binding-transform endpointwithastro @astrojs/cloudflare
CVE-2026-41067Astro: XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypasswithastro astro
CVE-2026-33768Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`withastro astro
CVE-2026-29772Astro: Memory exhaustion DoS due to missing request body size limit in Server Islandswithastro astro
CVE-2026-27829Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSizewithastro astro
CVE-2026-27729Astro has memory exhaustion DoS due to missing request body size limit in Server Actionswithastro astro
CVE-2025-66202Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765withastro astro
CVE-2025-65019Astro Cloudflare adapter has a Stored Cross Site Scripting vulnerability in /_image endpointwithastro astro
CVE-2025-64765Astro middleware authentication checks based on url.pathname can be bypassed via url encoded valueswithastro astro
CVE-2025-64745Astro development server error page vulnerable to reflected Cross-site Scriptingwithastro astro
CVE-2025-64525Astro: URL manipulation via unsanitized headers leads to path-based middleware protections bypass, potential…withastro astro
CVE-2025-59837astro allows bypass of image proxy domain validation leading to SSRF and potential XSSwithastro astro
CVE-2025-58179Astro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpointwithastro astro
40 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.