Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-27829 — Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize

Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in Astro's image pipeline allows bypassing `image.domains` / `image.remotePatterns` restrictions, enabling the server to fetch content…

astro \@astrojs\/node | Remote | Server-Side Request Forgery
Feb 26, 2026 Mar 09, 2026
Feb 26, 2026
Mar 09, 2026
Showing 20 of 6101 Results