Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-58179

35
FAUCET Score

CVE-2025-58179 is a Server-Side Request Forgery (SSRF) vulnerability affecting Astro web framework versions 11.0.3 through 12.6.5 when using the Cloudflare adapter with specific configurations. An attacker can bypass third-party domain restrictions in the image optimization endpoint, allowing unauthorized content to be served from the vulnerable origin. Rated as Medium severity (CVSS 6.5), this vulnerability has a low impact on confidentiality and integrity, with no authentication required for exploitation. While there is a Nuclei template available for detection, there is currently no evidence of active exploitation, Metasploit modules, or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 11.0.3, < 12.6.6CPE matchmatch criteria
cpe:2.3:a:astro:\@astrojs\/cloudflare:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

7.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.77%
Probability of exploitation in next 30 days
EPSS Percentile
52.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2025-58179 · Sep 12, 2025
This CVE's current EPSS score of 0.0077 is in the 32nd percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: @astrojs/cloudflareFixed in: 12.6.6

Vendor Advisories (1)

npmGHSA-qpr4-c339-7vq8high

Server-Side Request Forgery via /_image endpoint in Astro Cloudflare adapter

Sep 4, 2025

References

github.com / withastro/astro/commit/9ecf3598e2b29dd74614328fde3047ea90e67252
Patch
github.com / withastro/astro/security/advisories/GHSA-qpr4-c339-7vq8
ExploitVendor Advisory