CVE-2026-33769 is a medium severity vulnerability affecting the Astro web framework (versions 2.10.10 to 5.18.0) where unanchored wildcard matching in remotePatterns path enforcement allows for a remote allowlist bypass. This flaw enables an unauthenticated attacker to fetch paths outside an intended allowlisted prefix on an otherwise permitted host, resulting in a low confidentiality impact (CVSS 5.3). The attack vector is network-based with low complexity and requires no user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community attention, as indicated by its very low EPSS score and absence from the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.10.10, < 5.18.1CPE matchmatch criteria | cpe:2.3:a:astro:astro:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.