CVE-2026-33768Disclosure(astro / \@astrojs\/vercel)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch astro \@astrojs\/vercel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path header and x_astro_path query parameter to rewrite the internal request path, with no authentication whatsoever. On deployments without Edge Middleware, this lets anyone bypass Vercel's platform-level path restrictions entirely. The override preserves the original HTTP method and body, so this isn't limited to GET. POST, PUT, DELETE all land on the rewritten path. A Firewall rule blocking /admin/* does nothing when the request comes in as POST /api/health?x_astro_path=/admin/delete-user. This issue has been patched in version 10.0.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-441CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • \@astrojs\/vercel

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-24); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
\@astrojs\/vercel

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-24: 1Mentions · 2026-03-25: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 103-2403-25
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-241
Disclosure1
2026-03-251
Patch1
Full discourse2 posts
  • そば好き@soba_dev
    Patch

    Webフレームワーク「Astro」において、特定条件においてVercelのプラットフォームレベルのファイアウォールを回避可能な脆弱性を報告し、修正されました。(CVE-2026-33768) 私の初CVEです! Astroは私もお世話になっているフレームワークなので、貢献できたことはとても嬉しく思います。 今後も、お世話になっているOSSには積極的に貢献していきます! https://github.com/withastro/astro/security/advisories/GHSA-mr6q-rp88-fx84

    Post summary

    The advisory announces that a firewall‑bypass vulnerability (CVE‑2026‑33768) in Astro has been discovered and fixed, with no PoC or active exploitation evidence shared.

    01121605
    280 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33768 - Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path` Intel Report: https://ift.tt/cZpXPzI

    Post summary

    The alert announces CVE-2026-33768, a path override vulnerability in Astro, without evidence of active exploitation, mitigations, or a proof of concept.

    0000035
    286 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appastro\@astrojs\/vercel---

Explore more