@astrojs/cloudflare
Deploy your site to Cloudflare Workers
Security Advisories for @astrojs/cloudflare in npm
Low
about 1 month ago
Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4)
npm
@astrojs/cloudflare
Potential
High
7 months ago
Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
npm
astro
Potential
High
9 months ago
Server-Side Request Forgery via /_image endpoint in Astro Cloudflare adapter
npm
@astrojs/cloudflare
Potential
Moderate
10 months ago
Astro allows unauthorized third-party images in _image endpoint
npm
astro, @astrojs/node
Potential
Moderate
10 months ago
@astrojs/node's trailing slash handling causes open redirect issue
npm
@astrojs/node
Potential
Moderate
10 months ago
Astros's duplicate trailing slash feature leads to an open redirection security issue
npm
astro
Potential
High
over 1 year ago
Astro's server source code is exposed to the public if sourcemaps are enabled
npm
astro
Potential
Potential
Moderate
over 1 year ago
DOM Clobbering Gadget found in astro's client-side router that leads to XSS
npm
astro