astro
30 known vulnerabilities · 0 critical · 0 high
Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values
Astro's server source code is exposed to the public if sourcemaps are enabled
Astro development server error page is vulnerable to reflected Cross-site Scripting
Astro: Remote allowlist bypass via unanchored matchPathname wildcard
Astros's duplicate trailing slash feature leads to an open redirection security issue
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
Astro: XSS in define:vars via incomplete </script> tag sanitization
Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint
DOM Clobbering Gadget found in astro's client-side router that leads to XSS
Astro vulnerable to reflected XSS via the server islands feature
Uptime Kuma's Regular Expression in pushdeeer and whapi file Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`
Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands
@octokit/endpoint has a Regular Expression in parse that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
@octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
@octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Malicious code in storyblok-rich-text-astro-renderer-workspace (npm)
Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize
Astro has Full-Read SSRF in error rendering via Host: header injection
Astro: Cache Poisoning due to incorrect error handling when if-match header is malformed
@octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Astro has memory exhaustion DoS due to missing request body size limit in Server Actions
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
Malicious code in spaceman-an-astronauts-unlikely-journey-to-unlock-the-secrets-of-the-universe-by-mike-massimino-on-a (npm)
Malicious code in astro-scripts (npm)
Malicious code in astroia (npm)