VulnSea

astro has 10 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 3 in the 90 before. The busiest recent month was July 2026 with 5. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-79 (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
7 prev 3

Products

  • astro 10
10
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

astro vulnerabilities

CVEs affecting astro, newest first. Open any entry for full detail, references, and exploit status.

10 CVEsRSS

GHSA-26w7-cxv4-gfx2Critical· 9.8
2w ago

Astro: Remote code execution through AVIF image optimization

Astro: Remote code execution through AVIF image optimization

Midnightastro · astrovia GHSA
CVE-2026-84376Medium
2w ago

Astro is a web framework for content-driven websites

Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path from request pathnames using a string-prefix check without verifying a path-segment boundary. With base "/app", a reques…

Sunlitastro · astroEPSS 0.41%via NVD
CVE-2026-59727Low
2mo ago

Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands

Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands

Sunlitastro · astroEPSS 0.31%via GHSA
CVE-2026-59729Medium
2mo ago

Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)

Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)

Sunlitastro · astroEPSS 0.32%via GHSA
GHSA-8mv7-9c27-98vcMedium
2mo ago

Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered

Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered

Sunlitastro · astrovia GHSA
CVE-2026-59731High· 8.2
2mo ago

Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

Twilightastro · astroEPSS 0.47%via GHSA
GHSA-4g3v-8h47-v7g6Medium
2mo ago

Astro: Reflected XSS via unescaped View Transition animation properties

Astro: Reflected XSS via unescaped View Transition animation properties

Sunlitastro · astrovia GHSA
CVE-2026-50146High· 7.1
3mo ago

Astro: Reflected XSS via unescaped slot name

Astro: Reflected XSS via unescaped slot name

Twilightastro · astroEPSS 0.27%via GHSA
CVE-2026-54299High· 7.5
3mo ago

Astro: Host header SSRF in prerendered error page fetch

Astro: Host header SSRF in prerendered error page fetch

Twilightastro · astroEPSS 0.33%via GHSA
CVE-2026-54298Medium· 4.2
3mo ago

Astro: XSS via Unescaped Attribute Names in Spread Props

Astro: XSS via Unescaped Attribute Names in Spread Props

Sunlitastro · astroEPSS 0.23%via GHSA
astro vulnerabilities (CVEs) · VulnSea