Security changelog

Astro

27 fixes · 7 high/critical

Source: GitHub Advisory Database, pulled hourly. · Last checked Sep 21, 2026

Sep 2026

Astro: Remote code execution through AVIF image optimization

Affected: < 7.2.8Fixed in 7.2.8
mediumGHSA-376h-93r7-7g6fCVE-2026-84376
Sep 2026

Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base

Affected: <= 7.2.3Fixed in 7.2.4
mediumGHSA-8mv7-9c27-98vcCVE-2026-73423
Jul 2026

Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered

Affected: >= 7.0.0, < 7.0.6Fixed in 7.0.6
mediumGHSA-f48w-9m4c-m7f5CVE-2026-59729
Jul 2026

Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)

Affected: < 7.0.6Fixed in 7.0.6
lowGHSA-7pw4-f3q4-r2p2CVE-2026-59727
Jul 2026

Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands

Affected: >= 3.10.0, < 7.0.4Fixed in 7.0.4
highGHSA-vj59-8hwv-xxmvCVE-2026-59731
Jul 2026

Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

Affected: >= 6.4.7, < 6.4.8Fixed in 6.4.8
mediumGHSA-4g3v-8h47-v7g6CVE-2026-73422
Jul 2026

Astro: Reflected XSS via unescaped View Transition animation properties

Affected: >= 2.9.0, <= 7.0.9Fixed in 7.1.0
mediumGHSA-jrpj-wcv7-9fh9CVE-2026-54298
Jun 2026

Astro: XSS via Unescaped Attribute Names in Spread Props

Affected: < 6.4.6Fixed in 6.4.6
highGHSA-2pvr-wf23-7pc7CVE-2026-54299
Jun 2026

Astro: Host header SSRF in prerendered error page fetch

Affected: < 6.4.6Fixed in 6.4.6
highGHSA-8hv8-536x-4wqpCVE-2026-50146
Jun 2026

Astro: Reflected XSS via unescaped slot name

Affected: < 6.3.3Fixed in 6.3.3
Show all 17
lowGHSA-xr5h-phrj-8vxvCVE-2026-45028
May 2026

Astro: Server island encrypted parameters vulnerable to cross-component replay

Affected: < 6.1.10Fixed in 6.1.10
mediumGHSA-j687-52p2-xcffCVE-2026-41067
Apr 2026

Astro: XSS in define:vars via incomplete </script> tag sanitization

Affected: < 6.1.6Fixed in 6.1.6
lowGHSA-g735-7g2w-hh3fCVE-2026-33769
Mar 2026

Astro: Remote allowlist bypass via unanchored matchPathname wildcard

Affected: >= 2.10.10, < 5.18.1Fixed in 5.18.1
mediumGHSA-whqg-ppgf-wp8cCVE-2025-66202
Dec 2025

Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765

Affected: < 5.15.8Fixed in 5.15.8
mediumGHSA-fvmw-cj7j-j39qCVE-2025-65019
Nov 2025

Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint

Affected: < 5.15.9Fixed in 5.15.9
mediumGHSA-ggxq-hp9w-j794CVE-2025-64765
Nov 2025

Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values

Affected: < 5.15.8Fixed in 5.15.8
highGHSA-wrwg-2hg8-v723CVE-2025-64764
Nov 2025

Astro vulnerable to reflected XSS via the server islands feature

Affected: <= 5.15.6Fixed in 5.15.8
lowGHSA-x3h8-62x9-952gCVE-2025-64757
Nov 2025

Astro Development Server has Arbitrary Local File Read

Affected: < 5.14.3Fixed in 5.14.3
mediumGHSA-hr2q-hp5q-x767CVE-2025-64525
Nov 2025

Astro vulnerable to URL manipulation via headers, leading to middleware and CVE-2025-61925 bypass

Affected: >= 2.16.0, < 5.15.5Fixed in 5.15.5
lowGHSA-w2vj-39qv-7vh7CVE-2025-64745
Nov 2025

Astro development server error page is vulnerable to reflected Cross-site Scripting

Affected: >= 5.2.0, < 5.15.6Fixed in 5.15.6
highGHSA-qcpr-679q-rhm2CVE-2025-59837
Oct 2025

Astro's bypass of image proxy domain validation leads to SSRF and potential XSS

Affected: >= 5.13.4, < 5.13.10Fixed in 5.13.10
mediumGHSA-5ff5-9fcw-vg88CVE-2025-61925
Oct 2025

Astro's `X-Forwarded-Host` is reflected without validation

Affected: < 5.14.3Fixed in 5.14.3
mediumGHSA-xf8x-j4p2-f749CVE-2025-55303
Aug 2025

Astro allows unauthorized third-party images in _image endpoint

Affected: <= 4.16.18 · >= 5.0.0-alpha.0, < 5.13.2Fixed in 4.16.19, 5.13.2
mediumGHSA-cq8c-xv66-36gwCVE-2025-54793
Aug 2025

Astros's duplicate trailing slash feature leads to an open redirection security issue

Affected: >= 5.2.0, < 5.12.8Fixed in 5.12.8
highGHSA-49w6-73cw-chjrCVE-2024-56159
Dec 2024

Astro's server source code is exposed to the public if sourcemaps are enabled

Affected: <= 4.16.17 · >= 5.0.0-alpha.0, < 5.0.8Fixed in 4.16.18, 5.0.8
mediumGHSA-c4pw-33h3-35xwCVE-2024-56140
Dec 2024

Atro CSRF Middleware Bypass (security.checkOrigin)

Affected: < 4.16.17Fixed in 4.16.17
mediumGHSA-m85w-3h95-hcf9CVE-2024-47885
Oct 2024

DOM Clobbering Gadget found in astro's client-side router that leads to XSS

Affected: >= 3.0.0, < 4.16.1Fixed in 4.16.1