Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-58179

Опубликовано: 05 сент. 2025
Источник: nvd
CVSS3: 7.2
CVSS3: 6.5
EPSS Низкий

Описание

Astro is a web framework for content-driven websites. Versions 11.0.3 through 12.6.5 are vulnerable to SSRF when using Astro's Cloudflare adapter. When configured with output: 'server' while using the default imageService: 'compile', the generated image optimization endpoint doesn't check the URLs it receives, allowing content from unauthorized third-party domains to be served. a A bug in impacted versions of the @astrojs/cloudflare adapter for deployment on Cloudflare’s infrastructure, allows an attacker to bypass the third-party domain restrictions and serve any content from the vulnerable origin. This issue is fixed in version 12.6.6.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:astro:\@astrojs\/cloudflare:*:*:*:*:*:node.js:*:*
Версия от 11.0.3 (включая) до 12.6.6 (исключая)

EPSS

Процентиль: 45%
0.00225
Низкий

7.2 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.2
github
5 месяцев назад

Server-Side Request Forgery via /_image endpoint in Astro Cloudflare adapter

EPSS

Процентиль: 45%
0.00225
Низкий

7.2 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-918