OSS Support Hub / Web Framework

Node.js Web Framework NOASSERTION Latest: astro@6.3.3

Astro

Web framework optimised for building fast, content-focused websites with any UI component library

Project Health at a Glance

Live data from GitHub and npm, updated daily.

โญ
59.3K+6
GitHub Stars
๐Ÿ“ฆ
astro@6.3.3
Latest Release ยท Yesterday
๐Ÿ”„
0d
Avg. Release Cadence
๐Ÿ›
208
Open Issues
๐Ÿ“…
Today
Last Commit
โฌ‡๏ธ
2.7M
Weekly Downloads
๐Ÿ”’
10
Active CVEs

Data last fetched: 2026-05-15

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Astro's server source code is exposed to the public if sourcemaps are enabled

Published: 2024-12-19 Fixed in: 5.0.8

Astro's `X-Forwarded-Host` is reflected without validation

Published: 2025-10-10 Fixed in: 5.14.3

Atro CSRF Middleware Bypass (security.checkOrigin)

Published: 2024-12-18 Fixed in: 4.16.17

Astros's duplicate trailing slash feature leads to an open redirection security issue

Published: 2025-08-07 Fixed in: 5.12.8

Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint

Published: 2025-11-19 Fixed in: 5.15.9

Astro: Remote allowlist bypass via unanchored matchPathname wildcard

Published: 2026-03-26 Fixed in: 5.18.1

Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values

Published: 2025-11-19 Fixed in: 5.15.8

Astro vulnerable to URL manipulation via headers, leading to middleware and CVE-2025-61925 bypass

Published: 2025-11-13 Fixed in: 5.15.5

Astro: XSS in define:vars via incomplete </script> tag sanitization

Published: 2026-04-21 Fixed in: 6.1.6

DOM Clobbering Gadget found in astro's client-side router that leads to XSS

Published: 2024-10-14 Fixed in: 4.16.1

Alternatives to Astro

Other Web Framework projects in the Node.js ecosystem worth evaluating.

Support Options for Astro

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Astro โ€” without relying on volunteer maintainers.

Talk to an Expert โ†’