CVE-2026-25545Disclosure(astro / \@astrojs\/node)

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch astro \@astrojs\/node systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astro` or `500.astro`) are vulnerable to SSRF. If the `Host:` header is changed to an attacker's server, it will be fetched on `/500.html` and they can redirect this to any internal URL to read the response body through the first request. An attacker who can access the application without `Host:` header validation (eg. through finding the origin IP behind a proxy, or just by default) can fetch their own server to redirect to any internal IP. With this they can fetch cloud metadata IPs and interact with services in the internal network or localhost. For this to be vulnerable, a common feature needs to be used, with direct access to the server (no proxies). Version 9.5.4 fixes the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • \@astrojs\/node

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 10 signals
  • Disclosure: 10 classified signals
  • Peaked 4d ago at 4 mentions (2026-02-24); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Vendors
Products
\@astrojs\/node

Deep dive

Activity timeline10 mentions / 6d
01234Mentions · 2026-02-23: 2Mentions · 2026-02-24: 4Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Mentions · 2026-03-18: 1PoC Mentioned / Linked · 2026-02-23: 1Patch / Workaround · 2026-02-23: 1Patch / Workaround · 2026-02-24: 2Technical Details · 2026-02-23: 2Technical Details · 2026-02-24: 4Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 1Technical Details · 2026-03-18: 102-2302-2402-2702-2803-0103-18
Signal classification1 categories
Disclosure
10100.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-232
Disclosure2
2026-02-244
Disclosure4
2026-02-271
Disclosure1
2026-02-281
Disclosure1
2026-03-011
Disclosure1
2026-03-181
Disclosure1
Full discourse10 posts
  • pilvar (Philippe Dourassov)@pilvar222
    Disclosure

    And another finding for AI Pentest! This time on Astro (57.1k stars) Host header injection → HTTP redirect → full-read SSRF, writeup by the GOAT @J0R1AN CVE-2026-25545 advisory: https://github.com/withastro/astro/security/advisories/GHSA-qq67-mvv5-fw3g blog post: https://www.aikido.dev/blog/astro-full-read-ssrf-via-host-header-injection More to come 😉

    Post summary

    A new Astro vulnerability (CVE-2026-25545) involving host header injection that leads to full‑read SSRF has been disclosed, with a writeup and advisory available for remediation.

    08068282.8K
    1.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25545 Server-Side Request Forgery (SSRF) in Astro Web Framework Before ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25545 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    A new SSRF vulnerability (CVE-2026-25545) has been disclosed in the Astro Web Framework, with details available on Vulmon.

    0001050
    4.0K followersView on X
  • Aikido Community Japan@AikidoCommJP
    Disclosure

    ✅ 新着記事 AstroのHost Header InjectionによるSSRF脆弱性(CVE-2026-25545) https://aikido-community.jp/blog/astro-full-read-ssrf-via-host-header-injection #ベストプラクティス #Aikido #セキュリティ

    Post summary

    The Astro framework suffers a Host Header Injection that allows SSRF (CVE-2026-25545); the linked blog announces the vulnerability but does not provide PoC, exploit, active use, or patch details.

    0000054
    16 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-25545 (CVSS:6.9, HIGH) is Analyzed. Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered cus..https://nvd.nist.gov/vuln/detail/CVE-2026-25545 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-25545, a high‑severity vulnerability in Astro web framework affecting SSR pages before v9.5.4, with no PoC or exploit details provided.

    0000025
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-25545 (CVSS:6.9, HIGH) is Analyzed. Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered cus..https://nvd.nist.gov/vuln/detail/CVE-2026-25545 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-25545 with its CVSS score and a brief description of the affected Astro framework, but does not provide exploit code, patch details, or evidence of active exploitation.

    0000022
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-25545 (CVSS:6.9, HIGH) is Analyzed. Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered cus..https://nvd.nist.gov/vuln/detail/CVE-2026-25545 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-25545, providing its CVSS score, severity, and affected Astro framework version, but lacks details on PoC, exploitation, or patches.

    0000024
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25545 Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astro` or `500.astro`… https://www.cve.org/CVERecord?id=CVE-2026-25545

    Post summary

    Astro web framework has a vulnerability affecting server‑side rendered pages that return errors with prerendered custom error pages before version 9.5.4; upgrading to 9.5.4 resolves the issue.

    00000153
    56.5K followersView on X
  • Jason@flarestartcom
    Disclosure

    CVE-2026-25545: Astro-nomical Screw Up: Full-Read SSRF via Host Header Injection via http://Dev.to https://flarestart.com/article/cve-2026-25545-astro-nomical-screw-up-full-read-ssrf-via-host-header-injection-20260224 #DevNews #Security https://t.co/SENm1RJqBO

    Post summary

    The tweet announces CVE-2026-25545, describing a full-read SSRF via host header injection, and links to an article for further details.

    000002
    10 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25545: Astro-nomical Screw Up: Full-Read SSRF via Host Header Injection Astro, the darling framework of the static site generation world, stumbled into a classic web security pitfall: trusting the client. In versions prior to 9.5.4, Astro's S... https://cvereports.com/reports/CVE-2026-25545

    Post summary

    Astro framework versions before 9.5.4 are vulnerable to a full‑read SSRF via host header injection; the issue is fixed in version 9.5.4.

    0000047
    31 followersView on X
  • ninp0@ninp0
    Disclosure

    Astro SSRF Vulnerability: Host Header Injection in SSR Error Pages (CVE-2026-25545) https://www.aikido.dev/blog/astro-full-read-ssrf-via-host-header-injection

    Post summary

    The post announces a new CVE-2026-25545, describing a host header injection that leads to SSRF via Astro SSR error pages.

    0000067
    495 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appastro\@astrojs\/node-node.js-

Explore more