pilvar (Philippe Dourassov)[verified]@pilvar222Disclosure
A new Astro vulnerability (CVE-2026-25545) involving host header injection that leads to full‑read SSRF has been disclosed, with a writeup and advisory available for remediation.
Aikido Community Japan[verified]@AikidoCommJPDisclosure
The Astro framework suffers a Host Header Injection that allows SSRF (CVE-2026-25545); the linked blog announces the vulnerability but does not provide PoC, exploit, active use, or patch details.
Jason[verified]@flarestartcomDisclosure
The tweet announces CVE-2026-25545, describing a full-read SSRF via host header injection, and links to an article for further details.
ninp0[verified]@ninp0Disclosure
The post announces a new CVE-2026-25545, describing a host header injection that leads to SSRF via Astro SSR error pages.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A new SSRF vulnerability (CVE-2026-25545) has been disclosed in the Astro Web Framework, with details available on Vulmon.
CRAC Learning - Tech@cracbotDisclosure
The post announces CVE-2026-25545, a high‑severity vulnerability in Astro web framework affecting SSR pages before v9.5.4, with no PoC or exploit details provided.
CRAC Learning - Tech@cracbotDisclosure
The post references CVE-2026-25545 with its CVSS score and a brief description of the affected Astro framework, but does not provide exploit code, patch details, or evidence of active exploitation.
CRAC Learning - Tech@cracbotDisclosure
The post announces CVE-2026-25545, providing its CVSS score, severity, and affected Astro framework version, but lacks details on PoC, exploitation, or patches.