astro
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 28 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 14, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
Astro: XSS via Unescaped Attribute Names in Spread Props
Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)
Astro: Reflected XSS via unescaped slot name
Astro: Server island encrypted parameters vulnerable to cross-component replay
Astro: XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypass
Astro: Remote allowlist bypass via unanchored matchPathname wildcard
Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`
Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands
Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize
Monitor astro in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.