Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

withastro — Vulnerabilities & Security Advisories 42

Browse all 42 CVE security advisories affecting withastro. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Withastro is a static site generator designed to build fast, content-focused websites using modern web standards. Its core architecture relies on a component-based framework that compiles assets into static HTML, CSS, and JavaScript at build time. Security assessments have identified twenty-five Common Vulnerabilities and Exposures (CVEs) associated with the project, primarily stemming from its dependency ecosystem rather than the core engine itself. Historically, these vulnerabilities frequently involve remote code execution, cross-site scripting, and prototype pollution within third-party libraries used during the build process. While the static output reduces runtime attack surfaces, the build-time environment remains a critical vector for compromise. Notable incidents highlight risks related to insecure default configurations and insufficient input validation in plugin architectures. Developers must rigorously audit dependencies to mitigate these historically common vulnerability classes and ensure the integrity of the generated static assets.

Top products by withastro: astro @astrojs/cloudflare
CVE ID Title CVSS Severity Published
CVE-2026-102984 Astro: Malformed port in the Host header can crash the Node adapter — astro CWE-248 8.2 High 2026-09-30
CVE-2026-102983 Astro: Netlify Image CDN allowlist bypass enables SSRF — astro CWE-625 6.3 Medium 2026-09-30
CVE-2026-84376 Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base — astro CWE-187 6.3 Medium 2026-09-02
CVE-2026-73424 Astro: Unauthenticated path override in the @astrojs/vercel ISR function — astro CWE-441 6.5 Medium 2026-08-17
CVE-2026-73425 @astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped — astro CWE-185 3.7 Low 2026-08-12
CVE-2026-73423 Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered — astro CWE-352 5.1 Medium 2026-08-12
CVE-2026-73422 Astro: Reflected XSS via unescaped View Transition animation properties — astro CWE-79 5.3 Medium 2026-08-12
CVE-2026-59730 @astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect — astro CWE-601 2.1 Low 2026-07-27
CVE-2026-59728 @astrojs/rss: XML Injection via Unescaped RSS Feed Fields — astro CWE-91 4.3 Medium 2026-07-27
CVE-2026-59727 Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands — astro CWE-79 2.1 Low 2026-07-27
CVE-2026-59729 Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298) — astro CWE-79 5.1 Medium 2026-07-27
CVE-2026-59731 Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch — astro CWE-647 8.2 High 2026-07-08
CVE-2026-54299 Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL) — astro CWE-20 7.5 High 2026-06-22
CVE-2026-54298 Astro: XSS via Unescaped Attribute Names in Spread Props — astro CWE-79 4.2 Medium 2026-06-22
CVE-2026-50146 Astro: Reflected XSS via unescaped slot name — astro CWE-80 7.1 High 2026-06-22
CVE-2026-54300 @astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config — astro CWE-918 5.3 Medium 2026-06-22
CVE-2026-45028 Astro: Server island encrypted parameters vulnerable to cross-component replay — astro CWE-323 - - 2026-05-13
CVE-2026-41322 @astrojs/node: Cache Poisoning due to incorrect error handling when if-match header is malformed — astro CWE-525 5.3 Medium 2026-04-24
CVE-2026-41321 @astrojs/cloudflare: SSRF via redirect following in Cloudflare image-binding-transform endpoint — @astrojs/cloudflare CWE-918 2.2 Low 2026-04-24
CVE-2026-41067 Astro: XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypass — astro CWE-79 6.1 Medium 2026-04-24
CVE-2026-33769 Astro: Remote allowlist bypass via unanchored matchPathname wildcard — astro CWE-20 9.1 - 2026-03-24
CVE-2026-33768 Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path` — astro CWE-441 6.5 Medium 2026-03-24
CVE-2026-29772 Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands — astro CWE-770 5.9 Medium 2026-03-24
CVE-2026-27829 Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize — astro CWE-918 6.5 Medium 2026-02-26
CVE-2026-27729 Astro has memory exhaustion DoS due to missing request body size limit in Server Actions — astro CWE-770 5.9 Medium 2026-02-24
CVE-2026-25545 Astro has Full-Read SSRF in error rendering via Host: header injection — astro CWE-918 9.1 - 2026-02-24
CVE-2025-66202 Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765 — astro CWE-647 6.5 Medium 2025-12-08
CVE-2025-64765 Astro middleware authentication checks based on url.pathname can be bypassed via url encoded values — astro CWE-22 8.2AI High AI 2025-11-19
CVE-2025-64764 Astro is vulnerable to Reflected XSS via the server islands feature — astro CWE-80 7.1 High 2025-11-19
CVE-2025-65019 Astro Cloudflare adapter has a Stored Cross Site Scripting vulnerability in /_image endpoint — astro CWE-79 5.4 Medium 2025-11-19

This page lists every published CVE security advisory associated with withastro. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.