Security: withastro/astro
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Remote code execution through AVIF image optimizationGHSA-26w7-cxv4-gfx2 published
Aug 27, 2026 by matthewpCritical -
Netlify Image CDN allowlist bypass enables SSRFGHSA-4233-jc72-56c5 published
Aug 27, 2026 by matthewpModerate -
Authorization bypass from missing path-segment boundary check when stripping the configured baseGHSA-376h-93r7-7g6f published
Aug 27, 2026 by matthewpModerate -
Malformed port in the Host header can crash the Node adapterGHSA-qh8j-hqjv-7m4x published
Aug 27, 2026 by matthewpLow -
Reflected XSS via unescaped View Transition animation propertiesGHSA-4g3v-8h47-v7g6 published
Jul 17, 2026 by matthewpModerate -
@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escapedGHSA-hp3v-mfqw-h74c published
Jul 15, 2026 by matthewpLow -
Unauthenticated path override in the @astrojs/vercel ISR functionGHSA-x27w-589x-frm2 published
Jul 17, 2026 by matthewpModerate -
composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misorderedGHSA-8mv7-9c27-98vc published
Jul 17, 2026 by matthewpLow -
XSS via unescaped spread attribute names in custom element renderingGHSA-f48w-9m4c-m7f5 published
Jul 17, 2026 by matthewpLow -
XML injection in @astrojs/rss via unescaped source and enclosure fieldsGHSA-8j5q-mfj2-5q9q published
Jul 15, 2026 by matthewpModerate