HIGH🇵🇱 Wersja polska

CVE-2026-54299

CVSS 7.5v3.1pub. 2026-06-22upd. 2026-06-23

Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const prerender = true) fetch those pages over HTTP at runtime when an error occurs. The URL for this fetch is derived from request.url, which in turn gets its origin from the incoming Host header. When the Host header is not validated against allowedDomains, an attacker can point the fetch at an arbitrary host and read the response. This vulnerability is fixed in 6.4.6.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
  • Astro

    APP
    Astro
    < 6.4.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-50146HIGH7.1same product

Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot...

CVE-2025-64764HIGH7.1same product

Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server is...

CVE-2025-59837HIGH7.2same product

Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image ...

CVE-2024-56159HIGH7.8same product

Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated us...

CVE-2026-54298MEDIUM4.2same product

Astro to framework webowy. Przed wersją 6.4.6 funkcja spreadAttributes w pipeline'u server-side renderingu Ast...