Astro
This hub aggregates every CVE we track for Astro, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
46
CVEs tracked
2
Critical
9
High
0
In CISA KEV
Severity distribution
MEDIUM22HIGH9LOW3CRITICAL2
Monthly trend
1
0
2
0
0
0
0
0
0
0
3
1
2
6
1
0
3
3
3
2
4
7
4
2
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Astro.
- GHSA-26w7-cxv4-gfx2Astro: Remote code execution through AVIF image optimization
- CVE-2026-84376Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
- CVE-2026-73424Astro: Unauthenticated path override in the @astrojs/vercel ISR function6.5
- CVE-2026-73425@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped3.7
- CVE-2026-73423Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
- CVE-2026-73422Astro: Reflected XSS via unescaped View Transition animation properties
- CVE-2026-59730@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
- CVE-2026-59728@astrojs/rss: XML Injection via Unescaped RSS Feed Fields4.3
- CVE-2026-59727Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
- CVE-2026-59729Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
- GHSA-8mv7-9c27-98vcAstro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
- GHSA-4g3v-8h47-v7g6Astro: Reflected XSS via unescaped View Transition animation properties
- CVE-2026-59731Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch8.2
- CVE-2026-54299Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)7.5
- CVE-2026-54298Astro: XSS via Unescaped Attribute Names in Spread Props4.2
Product normalization is registry-driven with AI assist and human review. How it works