Live data from GitHub and npm, updated daily.
Data last fetched: 2026-05-15
10 active CVEs reported via OSV.dev
Astro's server source code is exposed to the public if sourcemaps are enabled
Astro's `X-Forwarded-Host` is reflected without validation
Atro CSRF Middleware Bypass (security.checkOrigin)
Astros's duplicate trailing slash feature leads to an open redirection security issue
Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint
Astro: Remote allowlist bypass via unanchored matchPathname wildcard
Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values
Astro vulnerable to URL manipulation via headers, leading to middleware and CVE-2025-61925 bypass
Astro: XSS in define:vars via incomplete </script> tag sanitization
DOM Clobbering Gadget found in astro's client-side router that leads to XSS
Other Web Framework projects in the Node.js ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Astro โ without relying on volunteer maintainers.
Talk to an Expert โ