withastro
OSS Librariesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting withastro.
- CVE-2026-84376Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
- CVE-2026-73424Astro: Unauthenticated path override in the @astrojs/vercel ISR function6.5
- CVE-2026-73425@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped3.7
- CVE-2026-73423Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
- CVE-2026-73422Astro: Reflected XSS via unescaped View Transition animation properties
- CVE-2026-59730@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
- CVE-2026-59728@astrojs/rss: XML Injection via Unescaped RSS Feed Fields4.3
- CVE-2026-59727Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
- CVE-2026-59729Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
- CVE-2026-59731Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch8.2
- CVE-2026-54299Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)7.5
- CVE-2026-54298Astro: XSS via Unescaped Attribute Names in Spread Props4.2
- CVE-2026-50146Astro: Reflected XSS via unescaped slot name7.1
- CVE-2026-54300@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config5.3
- CVE-2026-45028Astro: Server island encrypted parameters vulnerable to cross-component replay6.1