---
id: CVE-2025-64525
title: Astro is a web framework
summary: >-
  Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5
  which utilizeon-demand rendering, request headers `x-forwarded-proto` and
  `x-forwarded-port` are insecurely used, without sanitization, to build the
  URL. This …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-918
vendor: astro
product: astro
affected:
  - 'astro >= 2.16.0, < 5.15.5'
patched:
  - astro 5.15.5
published: '2025-11-13'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64525'
references:
  - url: >-
      https://github.com/withastro/astro/blob/970ac0f51172e1e6bff4440516a851e725ac3097/packages/astro/src/core/app/node.ts#L121
    label: security-advisories@github.com
  - url: >-
      https://github.com/withastro/astro/blob/970ac0f51172e1e6bff4440516a851e725ac3097/packages/astro/src/core/app/node.ts#L97
    label: security-advisories@github.com
  - url: >-
      https://github.com/withastro/astro/commit/dafbb1ba29912099c4faff1440033edc768af8b4
    label: security-advisories@github.com
  - url: 'https://github.com/withastro/astro/security/advisories/GHSA-hr2q-hp5q-x767'
    label: security-advisories@github.com
tags:
  - nvd
  - exploit-available
epss: 0.01162
epssPercentile: 0.66204
exploits:
  nuclei:
    - CVE-2025-64525
  checkedAt: '2026-10-07T21:54:50.424Z'
exploitAvailable: true
ingestedAt: '2026-10-07T21:54:15.033Z'
---

## Overview

Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` and `x-forwarded-port` are insecurely used, without sanitization, to build the URL. This has several consequences, the most important of which are: middleware-based protected route bypass (only via `x-forwarded-proto`), DoS via cache poisoning (if a CDN is present), SSRF (only via `x-forwarded-proto`), URL pollution (potential SXSS, if a CDN is present), and WAF bypass. Version 5.15.5 contains a patch.

## Affected

- `astro >= 2.16.0, < 5.15.5`

## Remediation

Upgrade past the affected range:

- `astro 5.15.5`
