Vulnerabilidades em withastro

35 resultados
Análise Vexday

A Astro acumula 31 vulnerabilidades no Vexday, com 9 publicadas nos últimos 90 dias, indicando pressão de segurança contínua. Nenhuma vulnerabilidade está sob exploração ativa ou classificada como crítica, reduzindo o risco imediato. A fraqueza dominante (CWE-918 - Server-Side Request Forgery) sugere problemas estruturais em validação de requisições que demandam revisão arquitetural.

CVE-2026-25545MEDIUMAstro has Full-Read SSRF in error rendering via Host: header injectionEPSS 1.8%CVE-2024-56159HIGHServer source code is exposed to the public if sourcemaps are enabledEPSS 1.5%CVE-2025-64525MEDIUMAstro: URL manipulation via unsanitized headers leads to path-based middleware protections bypass, potential SSRF/cache-poisoning, CVE-2025-61925 bypassEPSS 1.2%CVE-2025-58179HIGHAstro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpointEPSS 0.8%CVE-2025-55303MEDIUMUnauthorized third-party images in Astro’s _image endpointEPSS 0.6%CVE-2025-54793MEDIUMAstro: Duplicate trailing slash feature can lead to Open RedirectsEPSS 0.6%CVE-2025-55207MEDIUM@astrojs/node's trailing slash handling causes open redirect issueEPSS 0.6%CVE-2025-64765MEDIUMAstro middleware authentication checks based on url.pathname can be bypassed via url encoded valuesEPSS 0.5%CVE-2025-64764HIGHAstro is vulnerable to Reflected XSS via the server islands featureEPSS 0.5%CVE-2024-47885MEDIUMastro's client-side router has DOM Clobbering Gadget that leads to XSSEPSS 0.4%CVE-2026-27729MEDIUMAstro has memory exhaustion DoS due to missing request body size limit in Server ActionsEPSS 0.4%CVE-2025-64757LOWAstro Development Server is Vulnerable to Arbitrary Local File ReadEPSS 0.4%CVE-2025-61925MEDIUMAstro's `X-Forwarded-Host` is reflected with no validationEPSS 0.4%CVE-2026-29772MEDIUMAstro: Memory exhaustion DoS due to missing request body size limit in Server IslandsEPSS 0.4%CVE-2026-59730LOW@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirectEPSS 0.4%CVE-2026-54299HIGHAstro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)EPSS 0.3%CVE-2026-33768MEDIUMAstro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`EPSS 0.3%CVE-2025-59837HIGHastro allows bypass of image proxy domain validation leading to SSRF and potential XSSEPSS 0.3%CVE-2026-59729MEDIUMAstro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)EPSS 0.3%CVE-2026-33769LOWAstro: Remote allowlist bypass via unanchored matchPathname wildcardEPSS 0.3%