@astrojs/netlify
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @astrojs/netlifypage 1 of 1
- CVE-2026-102983MEDIUMCVSS 6.3EG 6.3fixed in 8.2.42026-09-30
Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL. Beca…
- CVE-2026-54300MEDIUMCVSS 5.3EG 5.3fixed in 7.0.132026-06-16
@astrojs/netlify is an adapter that allows Astro to deploy your hybrid or server rendered site to Netlify. Prior to 7.0.13, @astrojs/netlify converts Astro image.remotePatterns into Netlify Image CDN images.remote_images regular expression…
- CVE-2026-73425LOWCVSS 3.7EG 3.7fixed in 8.1.22026-08-12
Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remotePatterns entry into a regular expression written to .netlify/v1/config.json under images.remote_images for Netlify's …
Check whether @astrojs/netlify is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @astrojs/netlify CVEs against the assets you own.
Book a Demo →