CVE-2026-59731Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially decoded pathname after reaching the iterative URL decoder limit, while later rewrite route matching performs an additional decodeURI() operation and can resolve the request to a protected route. This issue is fixed in version 6.4.8.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-647

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-08); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-08: 2Mentions · 2026-08-04: 1Patch / Workaround · 2026-08-04: 1Technical Details · 2026-07-08: 1Technical Details · 2026-08-04: 107-0808-04
Signal classification1 categories
Disclosure
3100.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-07-082
Disclosure2
2026-08-041
Disclosure1
Full discourse3 posts
  • Marcin Dudek@MythThrazz
    Disclosure

    Here are the direct links to the most serious (High-severity) Astro CVEs: 1. CVE-2024-56159 (High) — Server source code exposure via sourcemaps NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-56159 GitHub Advisory: https://github.com/withastro/astro/security/advisories/GHSA-49w6-73cw-chjr 2. CVE-2025-64764 (High, CVSS 7.1) — Reflected XSS via server islands http://CVE.org: https://www.cve.org/CVERecord?id=CVE-2025-64764 NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-64764 GitHub Advisory: https://github.com/withastro/astro/security/advisories/GHSA-wrwg-2hg8-v723 3. CVE-2026-59731 (High, CVSS 8.2) — Authorization bypass (middleware path checks) Confirmed High in multiple trackers (Snyk, Hacktron, Release Alert) Related GitHub advisory: GHSA-vj59-8hwv-xxmv (searchable on the project’s security page) 4. CVE-2026-54299 (High, CVSS 7.5) — Host-header SSRF in prerendered error pages GitHub Advisory: https://github.com/withastro/astro/security/advisories/GHSA-2pvr-wf23-7pc7 5. CVE-2026-50146 (High, CVSS 7.1) — Reflected XSS via unescaped slot names Confirmed High in trackers and release notes Full official list of all Astro security advisories https://github.com/withastro/astro/security/advisories

    Post summary

    The post lists several high‑severity Astro CVEs, providing advisory links and basic technical details, serving mainly as a disclosure announcement without evidence of live exploitation or PoC.

    0001057
    1.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-59731 Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially decoded pathname after reaching the iterative URL … https://www.cve.org/CVERecord?id=CVE-2026-59731 ----- Traducción: CVE-2026-59731 Ast… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-59731 affecting Astro 6.4.7, describing a partial pathname decoding issue, but provides no PoC, exploit code, active exploitation, patch, or detailed technical classification.

    0000042
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-59731 Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially decoded pathname after reaching the iterative URL … https://www.cve.org/CVERecord?id=CVE-2026-59731

    Post summary

    The post announces the existence of CVE-2026-59731, describing a flaw in Astro’s path‑based authorization logic while providing no proof‑of‑concept, exploit, or patch information.

    00000772
    57.8K followersView on X

Explore more