Astro: Netlify Image CDN allowlist bypass enables SSRF
Published Sep 30, 2026
6.3
MEDIUMCVSS 4.0
EPSS 0.54%
Description
Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL. Because Netlify evaluates these expressions with RegExp.test(), an allowed origin appearing only in a source URL's path or query can satisfy image.domains or image.remotePatterns while the URL's actual host remains attacker-controlled. An unauthenticated request to the public /.netlify/images endpoint can therefore cause the Image CDN to request attacker-selected URLs and may probe or reach internal services. Netlify egress protections may constrain reachable targets, and image transformation limits direct response exfiltration; no confidentiality or integrity impact has been demonstrated. This issue is fixed in version 8.2.4.
Affected products
-
- Version >= 5.2.0, < 8.2.4StatusaffectedConstraints-
- Version
- Vendor n/a Product Netlify Defaultn/a
- Version >= 5.2.0, < 8.2.4StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
@astrojs/netlify
npm
Introduced 5.2.0 Fixed 8.2.4
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @astrojs/netlify | 5.2.0 | 8.2.4 |
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 30, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (6)
- https://github.com/advisories/GHSA-4233-jc72-56c5 Advisory
- https://github.com/withastro/astro/commit/e362d4cf540b27730482455c8fc02efe57d16702 x_refsource_MISC
- https://github.com/withastro/astro/pull/17752 x_refsource_MISC
- https://github.com/withastro/astro/releases/tag/@astrojs/netlify@8.2.4 x_refsource_MISC
- https://github.com/withastro/astro/security/advisories/GHSA-4233-jc72-56c5 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-102983
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-4233-jc72-56c5 | Advisory | |
| https://github.com/withastro/astro/commit/e362d4cf540b27730482455c8fc02efe57d16702 | x_refsource_MISC | |
| https://github.com/withastro/astro/pull/17752 | x_refsource_MISC | |
| https://github.com/withastro/astro/releases/tag/@astrojs/netlify@8.2.4 | x_refsource_MISC | |
| https://github.com/withastro/astro/security/advisories/GHSA-4233-jc72-56c5 | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-102983 |
Change history (0)
No recorded changes yet.