Astro
6 CVEs tracked since 2025. Since Nov 2025, none of them reached CISA KEV.
Astro CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-11 | 6 | 0 |
Products
The products that kept showing up in Astro's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Astro.
- CVE-2026-54299Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)7.5
- CVE-2026-54298Astro: XSS via Unescaped Attribute Names in Spread Props4.2
- CVE-2026-50146Astro: Reflected XSS via unescaped slot name7.1
- CVE-2026-45028Astro: Server island encrypted parameters vulnerable to cross-component replay6.1
- CVE-2026-41067Astro: XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypass6.1
- CVE-2026-33769Astro: Remote allowlist bypass via unanchored matchPathname wildcard5.3
- CVE-2026-33768Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`6.5
- CVE-2026-29772Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands5.9
- CVE-2026-27729Astro has memory exhaustion DoS due to missing request body size limit in Server Actions5.9
- CVE-2026-25545Astro has Full-Read SSRF in error rendering via Host: header injection8.6
- CVE-2025-66202Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-647656.5
- CVE-2025-64765Astro middleware authentication checks based on url.pathname can be bypassed via url encoded values5.3
- CVE-2025-64764Astro is vulnerable to Reflected XSS via the server islands feature7.1
- CVE-2025-65019Astro Cloudflare adapter has a Stored Cross Site Scripting vulnerability in /_image endpoint5.4
- CVE-2025-64757Astro Development Server is Vulnerable to Arbitrary Local File Read3.5
The record
- Peak rank
- #116 in Nov 2025
- Busiest month shown
- Nov 2025, 6 CVEs
- Months with a KEV entry
- 0 since Nov 2025
- Monthly snapshots
- 1 since 2025