@astrojs/netlify vulnerabilities
CVEs whose affected-version data names the @astrojs/netlify package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
GHSA-hp3v-mfqw-h74cLow· 3.7@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
▾ Sunlitastrojs · @astrojs/netlifyvia GHSA
CVE-2026-54300Medium· 5.3@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config
@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config
▾ Sunlitastrojs · @astrojs/netlifyEPSS 0.31%via GHSA