CVE Tools

Astro

46 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Astro, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Astro CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Astro CVEs per month
MonthCVEs
2024-101
2024-110
2024-122
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-083
2025-091
2025-102
2025-116
2025-121
2026-010
2026-023
2026-033
2026-043
2026-052
2026-064
2026-077
2026-084
2026-092

Severity

How the 46 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical26%
  • High925%
  • Medium2261%
  • Low38%

Latest CVEs

The 15 most recently published vulnerabilities affecting Astro.

  1. GHSA-26w7-cxv4-gfx2Astro: Remote code execution through AVIF image optimization—
  2. CVE-2026-84376Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base—
  3. CVE-2026-73424Astro: Unauthenticated path override in the @astrojs/vercel ISR function6.5
  4. CVE-2026-73425@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped3.7
  5. CVE-2026-73423Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered—
  6. CVE-2026-73422Astro: Reflected XSS via unescaped View Transition animation properties—
  7. CVE-2026-59730@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect—
  8. CVE-2026-59728@astrojs/rss: XML Injection via Unescaped RSS Feed Fields4.3
  9. CVE-2026-59727Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands—
  10. CVE-2026-59729Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)—
  11. GHSA-8mv7-9c27-98vcAstro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered—
  12. GHSA-4g3v-8h47-v7g6Astro: Reflected XSS via unescaped View Transition animation properties—
  13. CVE-2026-59731Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch8.2
  14. CVE-2026-54299Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)7.5
  15. CVE-2026-54298Astro: XSS via Unescaped Attribute Names in Spread Props4.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store