CVE Tools

Withastro

6 CVEs tracked since 2025. Since Nov 2025, none of them reached CISA KEV.

Withastro CVEs per month

Nov 2025 to Nov 2025. Point at a month, or focus the strip and use the arrow keys.
Withastro CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-1160

Products

The products that kept showing up in Withastro's monthly top three, with their CVEs summed over those months.

  1. Astro61 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Withastro.

  1. CVE-2026-84376Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base—
  2. CVE-2026-73424Astro: Unauthenticated path override in the @astrojs/vercel ISR function6.5
  3. CVE-2026-73425@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped3.7
  4. CVE-2026-73423Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered—
  5. CVE-2026-73422Astro: Reflected XSS via unescaped View Transition animation properties—
  6. CVE-2026-59730@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect—
  7. CVE-2026-59728@astrojs/rss: XML Injection via Unescaped RSS Feed Fields4.3
  8. CVE-2026-59727Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands—
  9. CVE-2026-59729Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)—
  10. CVE-2026-59731Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch8.2
  11. CVE-2026-54299Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)7.5
  12. CVE-2026-54298Astro: XSS via Unescaped Attribute Names in Spread Props4.2
  13. CVE-2026-50146Astro: Reflected XSS via unescaped slot name7.1
  14. CVE-2026-54300@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config5.3
  15. CVE-2026-45028Astro: Server island encrypted parameters vulnerable to cross-component replay6.1

The record

Peak rank
#139 in Nov 2025
Busiest month shown
Nov 2025, 6 CVEs
Months with a KEV entry
0 since Nov 2025
Monthly snapshots
1 since 2025
Withastro's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store