Astro is a web framework and static site generation platform with a modestly sized but prominent product footprint spanning the core framework and integration modules for deployment targets such as Cloudflare, Vercel, and Node.js. The vendor's vulnerability exposure is characterized by a web-application attack surface: input-handling and request-processing weaknesses including cross-site scripting, server-side request forgery, path traversal, and cross-site request forgery recur across its components and deployment contexts. Vulnerabilities affecting Astro frequently acquire public exploit tooling, reflecting the ease of demonstration and reproduction in web framework flaws. The recurring weakness classes are endemic to frameworks that bridge server-side rendering, static generation, and dynamic content—contexts where input validation, output encoding, and request isolation demand careful engineering. Defenders should prioritize this vendor's updates, particularly for internet-exposed applications and dynamic rendering deployments; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Astro over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25545HIGH Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astro` or `500.astro`) are vulnerab | Feb 24, 2026 | 8.6 | 41 | NO | YES |
CVE-2025-58179MEDIUM Astro is a web framework for content-driven websites. Versions 11.0.3 through 12.6.5 are vulnerable to SSRF when using Astro's Cloudflare adapter. When configured with output: 'ser | Sep 5, 2025 | 6.5 | 35 | NO | YES |
CVE-2025-64525MEDIUM Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` and `x-forwarded-port` are insec | Nov 13, 2025 | 6.5 | 33 | NO | YES |
CVE-2025-54793MEDIUM Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulnerability in the trailing slash redirection logic when handlin | Aug 8, 2025 | 6.1 | 33 | NO | YES |
CVE-2025-55303MEDIUM Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimization endpoint in projects deployed with on-demand rendering | Aug 19, 2025 | 6.1 | 31 | NO | YES |
CVE-2026-54299HIGH Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const prerender = true) fetch those pages over HTTP at runtime when | Jun 22, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-64764MEDIUM Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feature is used in the targeted application, regardless of what | Nov 19, 2025 | 5.4 | 30 | NO | YES |
CVE-2026-33768CRITICAL Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path header and x_astro_path query parameter to rewrite the internal | Mar 24, 2026 | 9.1 | 28 | NO | NO |
CVE-2024-56159MEDIUM Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read parts of the server source code. During build, along with c | Dec 19, 2024 | 5.3 | 26 | NO | YES |
CVE-2026-29772HIGH Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full request body as JSON without enforcing a size limit. Because JSON | Mar 24, 2026 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Astro.
Media articles that mention a CVE ID that affects a product developed by Astro — matched by CVE ID, not by vendor name.