Vulnerability index

Browse CVEs

25 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Astro HIGH 7.5
CVE-2026-54299

Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const prerender = true) fetch those …

Fix: 6.4.6+
Fix from $1,950 2026-06-22
Astro MEDIUM 6.1
CVE-2026-54298

Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterates over object keys and passe…

Fix: 6.4.6+
Fix from $1,600 2026-06-22
Astro MEDIUM 6.1
CVE-2026-50146

Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content into a data-astro-template att…

Fix: 6.3.3+
Fix from $1,600 2026-06-22
Astro MEDIUM 6.1
CVE-2026-45028

Astro is a web framework. Astro versions prior to 6.1.10 used AES-GCM encryption to protect the confidentiality and integrity of server island props …

Fix: 6.1.10+
Fix from $1,600 2026-05-13
Astro MEDIUM 6.1
CVE-2026-41067

Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a case-sensitive regex /<\/scr…

Fix: 6.1.6+
Fix from $1,600 2026-04-24
\@astrojs\/vercel CRITICAL 9.1
CVE-2026-33768

Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path header and x_astro_path query par…

Fix: 10.0.2+
Fix from $2,300 2026-03-24
Astro MEDIUM 5.3
CVE-2026-33769

Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path enforcement for remote URLs …

Fix: 5.18.1+
Fix from $1,600 2026-03-24
\@astrojs\/node HIGH 7.5
CVE-2026-29772

Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full request body as JSON without enfor…

Fix: 10.0.0+
Fix from $1,950 2026-03-24
\@astrojs\/node HIGH 7.2
CVE-2026-27829

Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in Astro's image pipeline allows bypassing `image.domains` / `image.remotePatterns` …

Fix: 9.5.4+
Fix from $1,950 2026-02-26
\@astrojs\/node HIGH 7.5
CVE-2026-27729

Astro is a web framework. In versions 9.0.0 through 9.5.3, Astro server actions have no default request body size limit, which can lead to memory exh…

Fix: 9.5.4+
Fix from $1,950 2026-02-24
\@astrojs\/node HIGH 8.6
CVE-2026-25545

Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astr…

Fix: 9.5.4+
Fix from $1,950 2026-02-24
Astro MEDIUM 6.5
CVE-2025-66202

Astro is a web framework. Versions 5.15.7 and below have a double URL encoding bypass which allows any unauthenticated attacker to bypass path-based …

Fix: 5.15.8+
Fix from $1,600 2025-12-09
Astro MEDIUM 6.1
CVE-2025-65019

Astro is a web framework. Prior to version 5.15.9, when using Astro's Cloudflare adapter (@astrojs/cloudflare) with output: 'server', the image optim…

Fix: 5.15.9+
Fix from $1,600 2025-11-19
Astro MEDIUM 5.4
CVE-2025-64764

Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feature is used in the targeted a…

Fix: 5.15.8+
Fix from $1,600 2025-11-19
Astro MEDIUM 5.3
CVE-2025-64765

Astro is a web framework. Prior to version 5.15.8, a mismatch exists between how Astro normalizes request paths for routing/rendering and how the app…

Fix: 5.15.8+
Fix from $1,600 2025-11-19
Astro MEDIUM 6.1
CVE-2025-64745

Astro is a web framework. Starting in version 5.2.0 and prior to version 5.15.6, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Astro…

Fix: 5.15.6+
Fix from $1,600 2025-11-13
Astro MEDIUM 6.5
CVE-2025-64525

Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` a…

Fix: 5.15.5+
Fix from $1,600 2025-11-13
Astro HIGH 7.2
CVE-2025-59837

Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy domain validation can be bypassed…

Fix: 5.13.10+
Fix from $1,950 2025-10-28
Astro MEDIUM 6.5
CVE-2025-61925

Astro is a web framework. Prior to version 5.14.2, Astro reflects the value in `X-Forwarded-Host` in output when using `Astro.url` without any valida…

Fix: 5.14.2+
Fix from $1,600 2025-10-10
\@astrojs\/cloudflare MEDIUM 6.5
CVE-2025-58179

Astro is a web framework for content-driven websites. Versions 11.0.3 through 12.6.5 are vulnerable to SSRF when using Astro's Cloudflare adapter. Wh…

Fix: 12.6.6+
Fix from $1,600 2025-09-05
Astro MEDIUM 6.1
CVE-2025-55303

Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimization endpoint in projects dep…

Fix: 4.16.18 / 5.13.2+
Fix from $1,600 2025-08-19
Astro MEDIUM 6.1
CVE-2025-54793

Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulnerability in the trailing slash…

Fix: 5.12.7+
Fix from $1,600 2025-08-08
Astro MEDIUM 5.3
CVE-2024-56159

Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read parts of the server source c…

Fix: 4.16.18 / 5.0.8+
Fix from $1,600 2024-12-19
Astro MEDIUM 6.5
CVE-2024-56140

Astro is a web framework for content-driven websites. In affected versions a bug in Astro’s CSRF-protection middleware allows requests to bypass CSRF…

Fix: 4.16.17+
Fix from $1,600 2024-12-18
Astro MEDIUM 5.4
CVE-2024-47885

The Astro web framework has a DOM Clobbering gadget in the client-side router starting in version 3.0.0 and prior to version 4.16.1. It can lead to c…

Fix: 4.16.1+
Fix from $1,600 2024-10-14