Live data from GitHub and npm, updated daily.
Data last fetched: 2026-08-24
10 active CVEs reported via OSV.dev
Astro: Host header SSRF in prerendered error page fetch
Astro's server source code is exposed to the public if sourcemaps are enabled
Astro: Reflected XSS via unescaped View Transition animation properties
Astro's `X-Forwarded-Host` is reflected without validation
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Astro: Reflected XSS via unescaped slot name
Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
Atro CSRF Middleware Bypass (security.checkOrigin)
Astros's duplicate trailing slash feature leads to an open redirection security issue
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
Get SLA-backed support, security patches, and direct access to senior engineers for Astro — without relying on volunteer maintainers.