CVE-2026-102983

Source
https://cve.org/CVERecord?id=CVE-2026-102983
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102983.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-102983
Aliases
Published
2026-09-30T14:32:03Z
Modified
2026-10-02T03:47:25Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Astro: Netlify Image CDN allowlist bypass enables SSRF
Details

Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL. Because Netlify evaluates these expressions with RegExp.test(), an allowed origin appearing only in a source URL's path or query can satisfy image.domains or image.remotePatterns while the URL's actual host remains attacker-controlled. An unauthenticated request to the public /.netlify/images endpoint can therefore cause the Image CDN to request attacker-selected URLs and may probe or reach internal services. Netlify egress protections may constrain reachable targets, and image transformation limits direct response exfiltration; no confidentiality or integrity impact has been demonstrated. This issue is fixed in version 8.2.4.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-625",
        "CWE-918"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102983.json"
}
References

Affected packages

Git / github.com/withastro/astro

Affected ranges

Type
GIT
Repo
https://github.com/withastro/astro
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "5.2.0"
        },
        {
            "fixed":  "8.2.4"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

@astrojs/check@0.*
@astrojs/check@0.9.10
@astrojs/cloudflare@14.*
@astrojs/cloudflare@14.0.1
@astrojs/cloudflare@14.0.2
@astrojs/cloudflare@14.1.0
@astrojs/cloudflare@14.1.1
@astrojs/cloudflare@14.1.2
@astrojs/cloudflare@14.1.3
@astrojs/cloudflare@14.1.4
@astrojs/cloudflare@14.1.5
@astrojs/cloudflare@14.1.6
@astrojs/cloudflare@14.1.7
@astrojs/cloudflare@14.2.0
@astrojs/cloudflare@14.2.1
@astrojs/cloudflare@14.2.2
@astrojs/cloudflare@14.2.3
@astrojs/internal-helpers@0.*
@astrojs/internal-helpers@0.10.1
@astrojs/internal-helpers@0.10.2
@astrojs/internal-helpers@0.10.3
@astrojs/internal-helpers@0.10.4
@astrojs/language-server@2.*
@astrojs/language-server@2.16.11
@astrojs/language-server@2.16.12
@astrojs/language-server@2.16.13
@astrojs/language-server@2.16.14
@astrojs/markdoc@2.*
@astrojs/markdoc@2.0.1
@astrojs/markdoc@2.0.2
@astrojs/markdoc@2.0.3
@astrojs/markdoc@2.0.4
@astrojs/markdoc@2.0.5
@astrojs/markdoc@2.0.6
@astrojs/markdoc@2.0.7
@astrojs/markdoc@2.0.8
@astrojs/markdown-remark@7.*
@astrojs/markdown-remark@7.2.1
@astrojs/markdown-remark@7.2.2
@astrojs/markdown-remark@7.2.3
@astrojs/markdown-remark@7.2.4
@astrojs/markdown-satteri@0.*
@astrojs/markdown-satteri@0.3.3
@astrojs/markdown-satteri@0.3.4
@astrojs/markdown-satteri@0.3.5
@astrojs/markdown-satteri@0.3.6
@astrojs/markdown-satteri@0.3.7
@astrojs/mdx@7.*
@astrojs/mdx@7.0.1
@astrojs/mdx@7.0.2
@astrojs/mdx@7.0.3
@astrojs/mdx@7.0.4
@astrojs/mdx@7.0.5
@astrojs/mdx@7.0.6
@astrojs/mdx@7.0.7
@astrojs/netlify@8.*
@astrojs/netlify@8.1.0
@astrojs/netlify@8.1.1
@astrojs/netlify@8.1.2
@astrojs/netlify@8.1.3
@astrojs/netlify@8.2.0
@astrojs/netlify@8.2.1
@astrojs/netlify@8.2.2
@astrojs/netlify@8.2.3
@astrojs/node@11.*
@astrojs/node@11.0.1
@astrojs/node@11.0.2
@astrojs/node@11.0.3
@astrojs/node@11.1.0
@astrojs/node@11.1.1
@astrojs/node@11.1.2
@astrojs/node@11.1.3
@astrojs/node@11.1.4
@astrojs/preact@6.*
@astrojs/preact@6.0.1
@astrojs/preact@6.0.2
@astrojs/preact@6.0.3
@astrojs/preact@6.0.4
@astrojs/react@6.*
@astrojs/react@6.0.1
@astrojs/react@6.0.2
@astrojs/react@6.0.3
@astrojs/react@6.0.4
@astrojs/rss@4.*
@astrojs/rss@4.0.19
@astrojs/solid-js@7.*
@astrojs/solid-js@7.0.1
@astrojs/solid-js@7.0.2
@astrojs/svelte@9.*
@astrojs/svelte@9.0.1
@astrojs/telemetry@3.*
@astrojs/telemetry@3.3.3
@astrojs/ts-plugin@1.*
@astrojs/ts-plugin@1.10.10
@astrojs/ts-plugin@1.10.11
@astrojs/underscore-redirects@1.*
@astrojs/underscore-redirects@1.0.4
@astrojs/upgrade@0.*
@astrojs/upgrade@0.7.3
@astrojs/upgrade@0.7.4
@astrojs/vercel@11.*
@astrojs/vercel@11.0.1
@astrojs/vercel@11.0.2
@astrojs/vercel@11.0.3
@astrojs/vercel@11.0.4
@astrojs/vercel@11.0.5
@astrojs/vercel@11.0.6
@astrojs/vercel@11.0.7
@astrojs/vue@7.*
@astrojs/vue@7.0.1
@astrojs/vue@7.0.2
astro-vscode@2.*
astro-vscode@2.16.17
astro-vscode@2.16.18
astro@7.*
astro@7.0.3
astro@7.0.4
astro@7.0.5
astro@7.0.6
astro@7.0.7
astro@7.0.8
astro@7.0.9
astro@7.1.0
astro@7.1.1
astro@7.1.2
astro@7.1.3
astro@7.1.4
astro@7.1.5
astro@7.1.6
astro@7.2.0
astro@7.2.1
astro@7.2.2
astro@7.2.3
astro@7.2.4
create-astro@5.*
create-astro@5.2.0
create-astro@5.2.1
create-astro@5.2.2
create-astro@5.2.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102983.json"