CVE-2026-54299Patch(astro / astro)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch astro astro systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const prerender = true) fetch those pages over HTTP at runtime when an error occurs. The URL for this fetch is derived from request.url, which in turn gets its origin from the incoming Host header. When the Host header is not validated against allowedDomains, an attacker can point the fetch at an arbitrary host and read the response. This vulnerability is fixed in 6.4.6.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • astro

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-23); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
astro

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-23: 1Mentions · 2026-08-04: 1Patch / Workaround · 2026-06-23: 1Technical Details · 2026-06-23: 1Technical Details · 2026-08-04: 106-2308-04
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-06-231
Patch1
2026-08-041
Disclosure1
Full discourse2 posts
  • Marcin Dudek@MythThrazz
    Disclosure

    Here are the direct links to the most serious (High-severity) Astro CVEs: 1. CVE-2024-56159 (High) — Server source code exposure via sourcemaps NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-56159 GitHub Advisory: https://github.com/withastro/astro/security/advisories/GHSA-49w6-73cw-chjr 2. CVE-2025-64764 (High, CVSS 7.1) — Reflected XSS via server islands http://CVE.org: https://www.cve.org/CVERecord?id=CVE-2025-64764 NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-64764 GitHub Advisory: https://github.com/withastro/astro/security/advisories/GHSA-wrwg-2hg8-v723 3. CVE-2026-59731 (High, CVSS 8.2) — Authorization bypass (middleware path checks) Confirmed High in multiple trackers (Snyk, Hacktron, Release Alert) Related GitHub advisory: GHSA-vj59-8hwv-xxmv (searchable on the project’s security page) 4. CVE-2026-54299 (High, CVSS 7.5) — Host-header SSRF in prerendered error pages GitHub Advisory: https://github.com/withastro/astro/security/advisories/GHSA-2pvr-wf23-7pc7 5. CVE-2026-50146 (High, CVSS 7.1) — Reflected XSS via unescaped slot names Confirmed High in trackers and release notes Full official list of all Astro security advisories https://github.com/withastro/astro/security/advisories

    Post summary

    The post announces several high‑severity Astro CVEs, providing links to advisories and describing each vulnerability’s nature and severity, but does not include exploits, PoC, or active exploitation evidence.

    0001057
    1.7K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-54299 - SSRF in #Astro SSR apps. Host header injection allows fetching arbitrary URLs via prerendered error pages. CVSS 7.5. Update to 6.4.6 immediately. #CVEAlert @astrodotbuild #infosec #sysadmin #devsecops #devops #developers More detailed info: https://www.valtersit.com/cve/CVE-2026-54299

    Post summary

    The post announces a patch for CVE-2026-54299, details an SSRF vulnerability through host header injection, and urges an immediate update to version 6.4.6.

    0001074
    962 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appastroastro-node.js-

Explore more