Products: 4
    Vulnerabilities: 23
    Known Exploited: 0
    0
    Critical Level Threats
    4
    High Level Threats
    17
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-45028

    Astro: Server island encrypted parameters vulnerable to cross-component replay

    Last Modified: May 14, 2026
    Published: May 13, 2026

    CVE-2026-41067

    Astro: XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypass

    Last Modified: Apr 27, 2026
    Published: Apr 24, 2026

    CVE-2026-33769

    Astro: Remote allowlist bypass via unanchored matchPathname wildcard

    Last Modified: Mar 27, 2026
    Published: Mar 24, 2026

    CVE-2026-33768

    Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`

    Last Modified: Mar 27, 2026
    Published: Mar 24, 2026

    CVE-2026-29772

    Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands

    Last Modified: Mar 26, 2026
    Published: Mar 24, 2026
    Items Per Page
    Astro Vulnerabilities & Security CVEs | CVE-DB