Astro是Astro开源的一个内容驱动网站的 web 框架。 Astro 2.16.0版本至5.15.5之前版本存在代码问题漏洞,该漏洞源于不安全使用x-forwarded-proto和x-forwarded-port请求标头,可能导致中间件保护路由绕过和服务器端请求伪造。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Astro 2.16.0 to 5.15.5 contains a broken access control caused by insecure use of unsanitized x-forwarded-proto and x-forwarded-port headers in URL building, letting attackers bypass middleware protection, cause DoS, SSRF, and URL pollution, exploit requires crafted headers. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-64525.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet