Astro

Astro

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.22%
  • Veröffentlicht 19.11.2025 16:40:47
  • Zuletzt bearbeitet 25.11.2025 15:09:57

Astro is a web framework. Prior to version 5.15.9, when using Astro's Cloudflare adapter (@astrojs/cloudflare) with output: 'server', the image optimization endpoint (/_image) contains a critical vulnerability in the isRemoteAllowed() function that u...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 19.11.2025 16:40:36
  • Zuletzt bearbeitet 20.11.2025 17:58:21

Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's development server that allows arbitrary local file read access through the image optimization endpoint. The vulnerability affects Astro d...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 13.11.2025 20:26:13
  • Zuletzt bearbeitet 25.11.2025 15:13:14

Astro is a web framework. Starting in version 5.2.0 and prior to version 5.15.6, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Astro's development server error pages when the `trailingSlash` configuration option is used. An attacker ...

Exploit
  • EPSS 1.09%
  • Veröffentlicht 13.11.2025 15:58:16
  • Zuletzt bearbeitet 25.11.2025 15:14:02

Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` and `x-forwarded-port` are insecurely used, without sanitization, to build the URL. This has several c...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 28.10.2025 19:54:28
  • Zuletzt bearbeitet 25.11.2025 15:16:15

Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy domain validation can be bypassed by using backslashes in the href parameter, allowing server-side requests to arbitrary URLs. This ca...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 10.10.2025 19:34:05
  • Zuletzt bearbeitet 04.12.2025 17:54:05

Astro is a web framework. Prior to version 5.14.2, Astro reflects the value in `X-Forwarded-Host` in output when using `Astro.url` without any validation. It is common for web servers such as nginx to route requests via the `Host` header, and forward...

Exploit
  • EPSS 0.6%
  • Veröffentlicht 19.08.2025 18:08:00
  • Zuletzt bearbeitet 25.11.2025 14:31:24

Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimization endpoint in projects deployed with on-demand rendering allows images from unauthorized third-party domains to be served. On-d...

  • EPSS 0.57%
  • Veröffentlicht 08.08.2025 00:02:38
  • Zuletzt bearbeitet 25.11.2025 15:14:31

Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulnerability in the trailing slash redirection logic when handling paths with double slashes. This allows an attacker to redirect users...

Exploit
  • EPSS 1.47%
  • Veröffentlicht 19.12.2024 19:15:08
  • Zuletzt bearbeitet 25.11.2025 13:38:29

Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read parts of the server source code. During build, along with client assets such as css and font files, the sourcemap files **for the...

  • EPSS 0.21%
  • Veröffentlicht 18.12.2024 21:15:08
  • Zuletzt bearbeitet 25.11.2025 13:42:59

Astro is a web framework for content-driven websites. In affected versions a bug in Astro’s CSRF-protection middleware allows requests to bypass CSRF checks. When the `security.checkOrigin` configuration option is set to `true`, Astro middleware will...