๐Ÿ” CVE Alert

CVE-2026-102983

UNKNOWN 0.0

Astro: Netlify Image CDN allowlist bypass enables SSRF

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL. Because Netlify evaluates these expressions with RegExp.test(), an allowed origin appearing only in a source URL's path or query can satisfy image.domains or image.remotePatterns while the URL's actual host remains attacker-controlled. An unauthenticated request to the public /.netlify/images endpoint can therefore cause the Image CDN to request attacker-selected URLs and may probe or reach internal services. Netlify egress protections may constrain reachable targets, and image transformation limits direct response exfiltration; no confidentiality or integrity impact has been demonstrated. This issue is fixed in version 8.2.4.

CWE CWE-625 CWE-918
Vendor withastro
Product astro
Published Sep 30, 2026
Last Updated Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for withastro astro

Be the first to know when new unknown vulnerabilities affecting withastro astro are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

withastro / astro
>= 5.2.0, < 8.2.4
@astrojs / netlify
>= 5.2.0, < 8.2.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/withastro/astro/security/advisories/GHSA-4233-jc72-56c5 github.com: https://github.com/withastro/astro/pull/17752 github.com: https://github.com/withastro/astro/commit/e362d4cf540b27730482455c8fc02efe57d16702 github.com: https://github.com/withastro/astro/releases/tag/@astrojs/[email protected]