CVE-2025-58179 is a Server-Side Request Forgery (SSRF) vulnerability affecting Astro web framework versions 11.0.3 through 12.6.5 when using the Cloudflare adapter with specific configurations. An attacker can bypass third-party domain restrictions in the image optimization endpoint, allowing unauthorized content to be served from the vulnerable origin. Rated as Medium severity (CVSS 6.5), this vulnerability has a low impact on confidentiality and integrity, with no authentication required for exploitation. While there is a Nuclei template available for detection, there is currently no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.0.3, < 12.6.6CPE matchmatch criteria | cpe:2.3:a:astro:\@astrojs\/cloudflare:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.