Astro
46 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Astro, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Astro CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 2 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 3 |
| 2025-09 | 1 |
| 2025-10 | 2 |
| 2025-11 | 6 |
| 2025-12 | 1 |
| 2026-01 | 0 |
| 2026-02 | 3 |
| 2026-03 | 3 |
| 2026-04 | 3 |
| 2026-05 | 2 |
| 2026-06 | 4 |
| 2026-07 | 7 |
| 2026-08 | 4 |
| 2026-09 | 2 |
Severity
How the 46 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High9
- Medium22
- Low3
Latest CVEs
The 15 most recently published vulnerabilities affecting Astro.
- GHSA-26w7-cxv4-gfx2Astro: Remote code execution through AVIF image optimization—
- CVE-2026-84376Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base—
- CVE-2026-73424Astro: Unauthenticated path override in the @astrojs/vercel ISR function6.5
- CVE-2026-73425@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped3.7
- CVE-2026-73423Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered—
- CVE-2026-73422Astro: Reflected XSS via unescaped View Transition animation properties—
- CVE-2026-59730@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect—
- CVE-2026-59728@astrojs/rss: XML Injection via Unescaped RSS Feed Fields4.3
- CVE-2026-59727Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands—
- CVE-2026-59729Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)—
- GHSA-8mv7-9c27-98vcAstro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered—
- GHSA-4g3v-8h47-v7g6Astro: Reflected XSS via unescaped View Transition animation properties—
- CVE-2026-59731Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch8.2
- CVE-2026-54299Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)7.5
- CVE-2026-54298Astro: XSS via Unescaped Attribute Names in Spread Props4.2
Product grouping is registry-driven, with AI assist and human review. How it works