@astrojs/node
npm9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @astrojs/nodepage 1 of 1
- CVE-2025-55207MEDIUMCVSS 5.5EG 5.5fixed in 9.4.12025-08-15
Astro is a web framework for content-driven websites. Following CVE-2025-54793 there's still an Open Redirect vulnerability in a subset of Astro deployment scenarios prior to version 9.4.1. Astro 5.12.8 addressed CVE-2025-54793 where https…
- CVE-2025-55303MEDIUMCVSS 6.1EG 6.1fixed in 9.1.12025-08-19
Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimization endpoint in projects deployed with on-demand rendering allows images from unauthorized third-party domains to be s…
- CVE-2026-102984HIGHCVSS 8.2EG 8.2fixed in 11.1.32026-09-30
Astro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter builds a request URL from the Host header, and a malformed port can make that URL invalid. The recovery path reuses the same malformed host an…
- CVE-2026-25545HIGHCVSS 8.6EG 8.6fixed in 9.5.42026-02-24
Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astro` or `500.astro`) are vulnerable to SSRF. If the `Host:` header is changed to an attacker…
- CVE-2026-27729HIGHCVSS 7.5EG 7.5fixed in 9.5.42026-02-24
Astro is a web framework. In versions 9.0.0 through 9.5.3, Astro server actions have no default request body size limit, which can lead to memory exhaustion DoS. A single large POST to a valid action endpoint can crash the server process o…
- CVE-2026-27829HIGHCVSS 7.2EG 7.2fixed in 9.5.42026-02-26
Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in Astro's image pipeline allows bypassing `image.domains` / `image.remotePatterns` restrictions, enabling the server to fetch content from unauthorized remote hosts. Astro p…
- CVE-2026-29772HIGHCVSS 7.5EG 7.5fixed in 10.0.02026-03-24
Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full request body as JSON without enforcing a size limit. Because JSON.parse() allocates a V8 heap object for every element in th…
- CVE-2026-41322MEDIUMCVSS 5.3EG 5.3fixed in 10.0.52026-04-24
@astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resources from _astro path with an incorrect/malformed if-match header returns a 500 error with a one year cache lifetime inste…
- CVE-2026-59730LOWCVSS 2.1EG 2.1fixed in 11.0.22026-07-20
Astro is a web framework for content-driven websites. In versions 8.1.0 through 11.0.1, when trailingSlash: 'always' is configured, the @astrojs/node standalone server's static file handler appends a trailing slash to request paths and iss…
Check whether @astrojs/node is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @astrojs/node CVEs against the assets you own.
Book a Demo →