CVE-2025-64525Medium· 6.5▾ TwilightPoC availableAstro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` and `x-forwarded-port` are insecurely used, without sanitization, to build the URL. This …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.2%
Nuclei ×1 (last check)
Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers x-forwarded-proto and x-forwarded-port are insecurely used, without sanitization, to build the URL. This has several consequences, the most important of which are: middleware-based protected route bypass (only via x-forwarded-proto), DoS via cache poisoning (if a CDN is present), SSRF (only via x-forwarded-proto), URL pollution (potential SXSS, if a CDN is present), and WAF bypass. Version 5.15.5 contains a patch.
astro >= 2.16.0, < 5.15.5Upgrade past the affected range:
astro 5.15.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102983Medium· 6.3Astro is a web framework for content-driven websites
CVE-2026-54299High· 7.5Astro: Host header SSRF in prerendered error page fetch
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents
CVE-2025-66202Medium· 6.5Astro is a web framework
CVE-2026-102984High· 8.2Astro is a web framework for content-driven websites
GHSA-26w7-cxv4-gfx2Critical· 9.8Astro: Remote code execution through AVIF image optimization