Vulnerabilidades em withastro

40 resultados
Análise Vexday

A Astro acumula 31 vulnerabilidades no Vexday, com 9 publicadas nos últimos 90 dias, indicando pressão de segurança contínua. Nenhuma vulnerabilidade está sob exploração ativa ou classificada como crítica, reduzindo o risco imediato. A fraqueza dominante (CWE-918 - Server-Side Request Forgery) sugere problemas estruturais em validação de requisições que demandam revisão arquitetural.

CVE-2026-41322MEDIUM@astrojs/node: Cache Poisoning due to incorrect error handling when if-match header is malformedEPSS 0.4%CVE-2025-64757LOWAstro Development Server is Vulnerable to Arbitrary Local File ReadEPSS 0.4%CVE-2026-27829MEDIUMAstro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSizeEPSS 0.4%CVE-2026-73424MEDIUMAstro: Unauthenticated path override in the @astrojs/vercel ISR functionEPSS 0.4%CVE-2026-59728MEDIUM@astrojs/rss: XML Injection via Unescaped RSS Feed FieldsEPSS 0.4%CVE-2026-33769LOWAstro: Remote allowlist bypass via unanchored matchPathname wildcardEPSS 0.4%CVE-2026-54299HIGHAstro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)EPSS 0.3%CVE-2025-59837HIGHastro allows bypass of image proxy domain validation leading to SSRF and potential XSSEPSS 0.3%CVE-2026-41321LOW@astrojs/cloudflare: SSRF via redirect following in Cloudflare image-binding-transform endpointEPSS 0.3%CVE-2025-66202MEDIUMAstro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765EPSS 0.3%CVE-2026-54300MEDIUM@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN configEPSS 0.3%CVE-2026-73425LOW@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escapedEPSS 0.3%CVE-2026-41067MEDIUMAstro: XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypassEPSS 0.3%CVE-2026-50146HIGHAstro: Reflected XSS via unescaped slot nameEPSS 0.3%CVE-2026-73423MEDIUMAstro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misorderedEPSS 0.3%CVE-2025-65019MEDIUMAstro Cloudflare adapter has a Stored Cross Site Scripting vulnerability in /_image endpointEPSS 0.3%CVE-2025-64745LOWAstro development server error page vulnerable to reflected Cross-site ScriptingEPSS 0.2%CVE-2026-54298MEDIUMAstro: XSS via Unescaped Attribute Names in Spread PropsEPSS 0.2%CVE-2024-56140MEDIUMBypass of CSRF Middleware in AstroEPSS 0.2%CVE-2026-45028LOWAstro: Server island encrypted parameters vulnerable to cross-component replayEPSS 0.2%