OSS Support Hub / Web Framework

Node.js Web Framework NOASSERTION Latest: create-astro@5.2.0

Astro

Web framework optimised for building fast, content-focused websites with any UI component library

Project Health at a Glance

Live data from GitHub and npm, updated daily.

60.6K+889
GitHub Stars
📦
create-astro@5.2.0
Latest Release · 4 days ago
🔄
0d
Avg. Release Cadence
🐛
132
Open Issues
📅
2 days ago
Last Commit
⬇️
3.5M
Weekly Downloads
🔒
10
Active CVEs

Data last fetched: 2026-06-29

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Astro: Host header SSRF in prerendered error page fetch

Published: 2026-06-16 Fixed in: 6.4.6

Astro's server source code is exposed to the public if sourcemaps are enabled

Published: 2024-12-19 Fixed in: 5.0.8

Astro's `X-Forwarded-Host` is reflected without validation

Published: 2025-10-10 Fixed in: 5.14.3

Astro: Reflected XSS via unescaped slot name

Published: 2026-06-16 Fixed in: 6.3.3

Atro CSRF Middleware Bypass (security.checkOrigin)

Published: 2024-12-18 Fixed in: 4.16.17

Astros's duplicate trailing slash feature leads to an open redirection security issue

Published: 2025-08-07 Fixed in: 5.12.8

Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint

Published: 2025-11-19 Fixed in: 5.15.9

Astro: Remote allowlist bypass via unanchored matchPathname wildcard

Published: 2026-03-26 Fixed in: 5.18.1

Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values

Published: 2025-11-19 Fixed in: 5.15.8

Astro vulnerable to URL manipulation via headers, leading to middleware and CVE-2025-61925 bypass

Published: 2025-11-13 Fixed in: 5.15.5

Alternatives to Astro

Other Web Framework projects in the Node.js ecosystem worth evaluating.

Support Options for Astro

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Astro — without relying on volunteer maintainers.