Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59731

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 8.2
EPSS Низкий

Описание

Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially decoded pathname after reaching the iterative URL decoder limit, while later rewrite route matching performs an additional decodeURI() operation and can resolve the request to a protected route. This issue is fixed in version 6.4.8.

EPSS

Процентиль: 19%
0.00267
Низкий

8.2 High

CVSS3

Дефекты

CWE-647

Связанные уязвимости

CVSS3: 8.2
github
около 1 месяца назад

Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

EPSS

Процентиль: 19%
0.00267
Низкий

8.2 High

CVSS3

Дефекты

CWE-647