{"id":"CVE-2025-64525","title":"Astro is a web framework","summary":"Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` and `x-forwarded-port` are insecurely used, without sanitization, to build the URL. This …","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-918"],"vendor":"astro","product":"astro","affected":["astro >= 2.16.0, < 5.15.5"],"patched":["astro 5.15.5"],"published":"2025-11-13","updated":"2026-10-07","sourceUpdated":"2026-10-07T21:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-64525","references":[{"url":"https://github.com/withastro/astro/blob/970ac0f51172e1e6bff4440516a851e725ac3097/packages/astro/src/core/app/node.ts#L121","label":"security-advisories@github.com"},{"url":"https://github.com/withastro/astro/blob/970ac0f51172e1e6bff4440516a851e725ac3097/packages/astro/src/core/app/node.ts#L97","label":"security-advisories@github.com"},{"url":"https://github.com/withastro/astro/commit/dafbb1ba29912099c4faff1440033edc768af8b4","label":"security-advisories@github.com"},{"url":"https://github.com/withastro/astro/security/advisories/GHSA-hr2q-hp5q-x767","label":"security-advisories@github.com"}],"tags":["nvd","exploit-available"],"epss":0.01162,"epssPercentile":0.66204,"exploits":{"nuclei":["CVE-2025-64525"],"checkedAt":"2026-10-07T21:54:50.424Z"},"exploitAvailable":true,"ingestedAt":"2026-10-07T21:54:15.033Z","slug":"CVE-2025-64525","body":"## Overview\n\nAstro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` and `x-forwarded-port` are insecurely used, without sanitization, to build the URL. This has several consequences, the most important of which are: middleware-based protected route bypass (only via `x-forwarded-proto`), DoS via cache poisoning (if a CDN is present), SSRF (only via `x-forwarded-proto`), URL pollution (potential SXSS, if a CDN is present), and WAF bypass. Version 5.15.5 contains a patch.\n\n## Affected\n\n- `astro >= 2.16.0, < 5.15.5`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `astro 5.15.5`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":35.8,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[]}