Exposição de Astro

JavaScript frameworks, Static site generator
51
score de exposição
35.026
sites usam
0
em exploração
1
críticos
Análise Vexday

Com 31 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, a taxa de exploração de Astro se mantém abaixo da média geral do catálogo, o que representa um perfil de risco operacional relativamente contido no momento. No entanto, a concentração de 9 vulnerabilidades surgidas nos últimos 90 dias indica um ritmo de descoberta recente elevado, merecendo atenção contínua de equipes de desenvolvimento e segurança. A falha mais comum é CWE-79 (Cross-Site Scripting), padrão que tende a surgir em frameworks de renderização web e exige controles rigorosos de sanitização de saída. A CVE mais perigosa identificada atualmente é CVE-2024-56159, com escore EPSS de aproximadamente 0,015, sugerindo baixa probabilidade de exploração imediata, porém seu caráter crítico recomenda priorização na aplicação de correções.

CVEs

36 resultados
CVE-2026-25545MEDIUMAstro has Full-Read SSRF in error rendering via Host: header injectionEPSS 1.8%CVE-2024-56159HIGHServer source code is exposed to the public if sourcemaps are enabledEPSS 1.5%CVE-2025-64525MEDIUMAstro: URL manipulation via unsanitized headers leads to path-based middleware protections bypass, potential SSRF/cache-poisoning, CVE-2025-61925 bypassEPSS 1.2%CVE-2025-58179HIGHAstro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpointEPSS 0.8%CVE-2025-55303MEDIUMUnauthorized third-party images in Astro’s _image endpointEPSS 0.6%CVE-2025-54793MEDIUMAstro: Duplicate trailing slash feature can lead to Open RedirectsEPSS 0.6%CVE-2025-55207MEDIUM@astrojs/node's trailing slash handling causes open redirect issueEPSS 0.6%CVE-2025-64765MEDIUMAstro middleware authentication checks based on url.pathname can be bypassed via url encoded valuesEPSS 0.5%CVE-2025-64764HIGHAstro is vulnerable to Reflected XSS via the server islands featureEPSS 0.5%CVE-2024-47885MEDIUMastro's client-side router has DOM Clobbering Gadget that leads to XSSEPSS 0.4%CVE-2026-27729MEDIUMAstro has memory exhaustion DoS due to missing request body size limit in Server ActionsEPSS 0.4%CVE-2025-64757LOWAstro Development Server is Vulnerable to Arbitrary Local File ReadEPSS 0.4%CVE-2025-61925MEDIUMAstro's `X-Forwarded-Host` is reflected with no validationEPSS 0.4%CVE-2026-29772MEDIUMAstro: Memory exhaustion DoS due to missing request body size limit in Server IslandsEPSS 0.4%CVE-2026-59730LOW@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirectEPSS 0.4%CVE-2026-54299HIGHAstro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)EPSS 0.3%CVE-2026-33768MEDIUMAstro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`EPSS 0.3%CVE-2025-59837HIGHastro allows bypass of image proxy domain validation leading to SSRF and potential XSSEPSS 0.3%CVE-2026-59729MEDIUMAstro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)EPSS 0.3%CVE-2026-33769LOWAstro: Remote allowlist bypass via unanchored matchPathname wildcardEPSS 0.3%