Security: withastro/astro
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Host header SSRF in prerendered error page fetchGHSA-2pvr-wf23-7pc7 published
Jun 12, 2026 by matthewpHigh -
XSS via Unescaped Attribute Names in Spread PropsGHSA-jrpj-wcv7-9fh9 published
Jun 12, 2026 by matthewpModerate -
@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN configGHSA-529g-xq4f-cw38 published
Jun 12, 2026 by matthewpModerate -
Reflected XSS via unescaped slot nameGHSA-8hv8-536x-4wqp published
Jun 12, 2026 by matthewpHigh -
Server island encrypted parameters vulnerable to cross-component replayGHSA-xr5h-phrj-8vxv published
May 7, 2026 by matthewpLow -
Cache Poisoning due to incorrect error handling when if-match header is malformedGHSA-c57f-mm3j-27q9 published
Apr 20, 2026 by matthewpModerate -
SSRF via redirect following in Cloudflare image-binding-transform endpoint (incomplete fix for GHSA-qpr4)GHSA-88gm-j2wx-58h6 published
Apr 20, 2026 by matthewpLow -
XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypassGHSA-j687-52p2-xcff published
Apr 20, 2026 by matthewpModerate -
Unauthenticated Path Override via `x-astro-path` / `x_astro_path`GHSA-mr6q-rp88-fx84 published
Mar 24, 2026 by matthewpModerate -
Memory exhaustion DoS due to missing request body size limit in Server IslandsGHSA-3rmj-9m5h-8fpv published
Mar 24, 2026 by matthewpModerate