{"id":"GHSA-hp3v-mfqw-h74c","title":"@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped","summary":"@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped","severity":"low","cvss":3.7,"cwe":["CWE-185"],"vendor":"astrojs","product":"@astrojs/netlify","ecosystem":"npm","affected":["@astrojs/netlify < 8.1.2"],"patched":["@astrojs/netlify 8.1.2"],"published":"2026-07-20","updated":"2026-07-20","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-hp3v-mfqw-h74c","references":[{"url":"https://github.com/withastro/astro/security/advisories/GHSA-hp3v-mfqw-h74c"},{"url":"https://github.com/withastro/astro/pull/17018"},{"url":"https://github.com/advisories/GHSA-529g-xq4f-cw38"},{"url":"https://github.com/advisories/GHSA-hp3v-mfqw-h74c"}],"tags":["ghsa","npm"],"ingestedAt":"2026-07-20T23:44:02.263Z","slug":"GHSA-hp3v-mfqw-h74c","body":"## Overview\n\n## Summary\n\nThe `@astrojs/netlify` adapter converts each `image.remotePatterns` entry into a regular expression that is written to `.netlify/v1/config.json` under `images.remote_images`. Netlify's Image CDN uses these regexes as the allowlist that decides which remote image URLs it will optimize. `remotePatternToRegex()` escapes `.` in the hostname but interpolates the literal `pathname` into the regex **without escaping regex metacharacters**. As a result, the generated allowlist is broader than the pattern the developer declared, and broader than Astro's canonical `matchPattern()` helper (which compares non-wildcard pathnames by exact string equality).\n\nThis is a residual of the same bug class addressed in CVE-2026-54300 (PR #17018, commit `1310277d`). That fix corrected wildcard semantics and added a `$` anchor but did not add metacharacter escaping for literal pathnames.\n\n## Details\n\nIn `packages/integrations/netlify/src/index.ts`, `remotePatternToRegex()` escapes dots in the hostname:\n\n```js\nregexStr += hostname.replace(/\\./g, '\\\\.');\n```\n\nbut interpolates the pathname unescaped in all three branches, e.g. the exact-match branch:\n\n```js\nregexStr += `(\\\\${pathname})`;\n```\n\nAny regex metacharacter in the literal path (`.`, `+`, `?`, `(`, `[`, ...) is therefore passed through raw. Because `.` matches any character (including `/`), a restrictive pattern is silently widened.\n\nThe security boundary on Netlify is the generated regex itself — Netlify's Image CDN enforces it directly and Astro's runtime `matchPattern()` is not in the loop for this path, so there is no compensating layer that re-validates the request.\n\n## Proof of Concept\n\nConfigure an SSR site with a literal pathname containing a `.`:\n\n```js\n// astro.config.mjs\nimage: {\n  remotePatterns: [{\n    protocol: 'https',\n    hostname: 'cdn.example.com',\n    pathname: '/img/v1.0/file',\n  }],\n}\n```\n\nRun `astro build` and inspect `.netlify/v1/config.json` `images.remote_images[0]`:\n\n```\nhttps://cdn\\.example\\.com(:[0-9]+)?(\\/img/v1.0/file)([?][^#]*)?$\n```\n\nTesting the generated regex:\n\n- `https://cdn.example.com/img/v1.0/file` -> MATCH (intended)\n- `https://cdn.example.com/img/v1X0/file` -> MATCH (bypass; the unescaped `.` matches any character)\n- `https://cdn.example.com/img/v1/0/file` -> MATCH (bypass; `.` also matches `/`, crossing a path segment)\n\nAstro's canonical `matchPattern()` (exact string equality on the pathname) rejects both bypass URLs.\n\n## Impact\n\nNetlify's Image CDN accepts optimization requests for URLs on the allowed host that the developer's `remotePatterns` entry was intended to exclude. The hostname remains correctly anchored, so the broadening is confined to the pathname dimension on an already-allowed host. Realistic impact depends on whether other images the developer meant to keep out of their CDN exist at metacharacter-adjacent paths on that host. This affects reasonable, non-permissive configurations, since any `pathname` containing a `.` (file extensions, version segments) is affected.\n\n## Patches\n\nA fix will escape all regex metacharacters in the literal portions of each `remotePatterns` component before interpolation, applying only Astro's documented wildcard semantics explicitly. A regression corpus validates the generated Netlify regexes against `@astrojs/internal-helpers`' `matchPattern()`.\n\n## Workarounds\n\nAvoid regex metacharacters (notably `.`) in `image.remotePatterns[].pathname` values, or scope the allowed host so that unintended paths are not reachable.\n\n## Credit\n\nReported by @sec-reex as part of an incomplete-patch measurement study (responsible disclosure).\n\n## Affected packages\n\n- `@astrojs/netlify < 8.1.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `@astrojs/netlify 8.1.2`","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":20.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}