Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Astro

First CVE: Oct 14, 2024Active for: 2 yearsTotal CVEs: 26
41.7
VTI Score
High

Astro is a web framework and static site generation platform with a modestly sized but prominent product footprint spanning the core framework and integration modules for deployment targets such as Cloudflare, Vercel, and Node.js. The vendor's vulnerability exposure is characterized by a web-application attack surface: input-handling and request-processing weaknesses including cross-site scripting, server-side request forgery, path traversal, and cross-site request forgery recur across its components and deployment contexts. Vulnerabilities affecting Astro frequently acquire public exploit tooling, reflecting the ease of demonstration and reproduction in web framework flaws. The recurring weakness classes are endemic to frameworks that bridge server-side rendering, static generation, and dynamic content—contexts where input validation, output encoding, and request isolation demand careful engineering. Defenders should prioritize this vendor's updates, particularly for internet-exposed applications and dynamic rendering deployments; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Astro over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 14, 2024
21 months ago
Most Recent CVE
Jun 22, 2026
33 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-25545HIGH
Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astro` or `500.astro`) are vulnerab
Feb 24, 20268.641NOYES
CVE-2025-58179MEDIUM
Astro is a web framework for content-driven websites. Versions 11.0.3 through 12.6.5 are vulnerable to SSRF when using Astro's Cloudflare adapter. When configured with output: 'ser
Sep 5, 20256.535NOYES
CVE-2025-64525MEDIUM
Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` and `x-forwarded-port` are insec
Nov 13, 20256.533NOYES
CVE-2025-54793MEDIUM
Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulnerability in the trailing slash redirection logic when handlin
Aug 8, 20256.133NOYES
CVE-2025-55303MEDIUM
Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimization endpoint in projects deployed with on-demand rendering
Aug 19, 20256.131NOYES
CVE-2026-54299HIGH
Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const prerender = true) fetch those pages over HTTP at runtime when
Jun 22, 20267.530NONO
CVE-2025-64764MEDIUM
Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feature is used in the targeted application, regardless of what
Nov 19, 20255.430NOYES
CVE-2026-33768CRITICAL
Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path header and x_astro_path query parameter to rewrite the internal
Mar 24, 20269.128NONO
CVE-2024-56159MEDIUM
Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read parts of the server source code. During build, along with c
Dec 19, 20245.326NOYES
CVE-2026-29772HIGH
Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full request body as JSON without enforcing a size limit. Because JSON
Mar 24, 20267.525NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
69%
23%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network25 (96.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (3.8%)
Attack Complexity
Low26 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (53.8%)
Unknown0 (0.0%)
Required12 (46.2%)
Privileges Required
Low1 (3.8%)
High0 (0.0%)
None25 (96.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
7 CVEs
26.9% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Astro.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Astro — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Astro's Products

View all 1 CNAs →

Top CWEs