Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-59731

около 2 месяцев назад

Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially decoded pathname after reaching the iterative URL decoder limit, while later rewrite route matching performs an additional decodeURI() operation and can resolve the request to a protected route. This issue is fixed in version 6.4.8.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-vj59-8hwv-xxmv

около 1 месяца назад

Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-59731

Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially decoded pathname after reaching the iterative URL decoder limit, while later rewrite route matching performs an additional decodeURI() operation and can resolve the request to a protected route. This issue is fixed in version 6.4.8.

CVSS3: 8.2
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-vj59-8hwv-xxmv

Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

CVSS3: 8.2
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу