@astrojs/node
npm8 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @astrojs/nodepage 1 of 1
- CVE-2025-55207MEDIUMCVSS 5.5EG 5.5✓ Fixed in 9.4.12025-08-15
Astro is a web framework for content-driven websites. Following CVE-2025-54793 there's still an Open Redirect vulnerability in a subset of Astro deployment scenarios prior to version 9.4.1. Astro 5.12.8 addressed CVE-2025-54793 where https…
- CVE-2025-55303MEDIUMCVSS 6.1EG 6.1✓ Fixed in 9.1.12025-08-19
Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimization endpoint in projects deployed with on-demand rendering allows images from unauthorized third-party domains to be s…
- CVE-2026-25545HIGHCVSS 8.6EG 8.6✓ Fixed in 9.5.42026-02-24
Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astro` or `500.astro`) are vulnerable to SSRF. If the `Host:` header is changed to an attacker…
- CVE-2026-27729HIGHCVSS 7.5EG 7.5✓ Fixed in 9.5.42026-02-24
Astro is a web framework. In versions 9.0.0 through 9.5.3, Astro server actions have no default request body size limit, which can lead to memory exhaustion DoS. A single large POST to a valid action endpoint can crash the server process o…
- CVE-2026-27829HIGHCVSS 7.2EG 7.2✓ Fixed in 9.5.42026-02-26
Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in Astro's image pipeline allows bypassing `image.domains` / `image.remotePatterns` restrictions, enabling the server to fetch content from unauthorized remote hosts. Astro p…
- CVE-2026-29772HIGHCVSS 7.5EG 7.5✓ Fixed in 10.0.02026-03-24
Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full request body as JSON without enforcing a size limit. Because JSON.parse() allocates a V8 heap object for every element in th…
- CVE-2026-41322MEDIUMCVSS 5.3EG 5.3✓ Fixed in 10.0.52026-04-24
@astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resources from _astro path with an incorrect/malformed if-match header returns a 500 error with a one year cache lifetime inste…
- CVE-2026-59730LOWCVSS 2.1EG 2.1✓ Fixed in 11.0.22026-07-20
Astro is a web framework for content-driven websites. In versions 8.1.0 through 11.0.1, when trailingSlash: 'always' is configured, the @astrojs/node standalone server's static file handler appends a trailing slash to request paths and iss…
Check whether @astrojs/node is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @astrojs/node CVEs against the assets you own.
Start Free Scan →