
Here are the direct links to the most serious (High-severity) Astro CVEs: 1. CVE-2024-56159 (High) — Server source code exposure via sourcemaps NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-56159 GitHub Advisory: https://github.com/withastro/astro/security/advisories/GHSA-49w6-73cw-chjr 2. CVE-2025-64764 (High, CVSS 7.1) — Reflected XSS via server islands http://CVE.org: https://www.cve.org/CVERecord?id=CVE-2025-64764 NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-64764 GitHub Advisory: https://github.com/withastro/astro/security/advisories/GHSA-wrwg-2hg8-v723 3. CVE-2026-59731 (High, CVSS 8.2) — Authorization bypass (middleware path checks) Confirmed High in multiple trackers (Snyk, Hacktron, Release Alert) Related GitHub advisory: GHSA-vj59-8hwv-xxmv (searchable on the project’s security page) 4. CVE-2026-54299 (High, CVSS 7.5) — Host-header SSRF in prerendered error pages GitHub Advisory: https://github.com/withastro/astro/security/advisories/GHSA-2pvr-wf23-7pc7 5. CVE-2026-50146 (High, CVSS 7.1) — Reflected XSS via unescaped slot names Confirmed High in trackers and release notes Full official list of all Astro security advisories https://github.com/withastro/astro/security/advisories
Post summary
The post lists multiple high‑severity Astro CVEs, providing their identifiers, severity levels, and links to advisories detailing the vulnerability types.

