<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 10:38:24 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-261348</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-261348</link>
      <description>EUVD-2026-261348</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-261348</guid>
    </item>
    <item>
      <title>fkie_cve-2025-65019</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-65019</link>
      <description>&lt;p&gt;Astro is a web framework. Prior to version 5.15.9, when using Astro&amp;#39;s Cloudflare adapter (@astrojs/cloudflare) with output: &amp;#39;server&amp;#39;, the image optimization endpoint (/_image) contains a critical vulnerability in the isRemoteAllowed() function that unconditionally allows data: protocol URLs. This enables Cross-Site Scripting (XSS) attacks through malicious SVG payloads, bypassing domain restrictions and Content Security Policy protections. This issue has been patched in version 5.15.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Astro is a web framework. Prior to version 5.15.9, when using Astro&amp;#39;s Cloudflare adapter (@astrojs/cloudflare) with output: &amp;#39;server&amp;#39;, the image optimization endpoint (/_image) contains a critical vulnerability in the isRemoteAllowed() function that unconditionally allows data: protocol URLs. This enables Cross-Site Scripting (XSS) attacks through malicious SVG payloads, bypassing domain restrictions and Content Security Policy protections. This issue has been patched in version 5.15.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-65019</guid>
    </item>
    <item>
      <title>GHSA-fvmw-cj7j-j39q — Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fvmw-cj7j-j39q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: astro&lt;/p&gt;
&lt;p&gt;**Summary**  
A Cross-Site Scripting (XSS) vulnerability exists in Astro when using the **@astrojs/cloudflare** adapter with `output: &amp;#39;server&amp;#39;`. The built-in image optimization endpoint (`/_image`) uses `isRemoteAllowed()` from Astro’s internal helpers, which **unconditionally allows `data:` URLs**. When the endpoint receives a valid `data:` URL pointing to a malicious SVG containing JavaScript, and the Cloudflare-specific implementation performs a **302 redirect back to the original `data:` URL**, the browser directly executes the embedded JavaScript. This completely bypasses any domain allow-listing (`image.domains` / `image.remotePatterns`) and typical Content Security Policy mitigations.&lt;/p&gt;
&lt;p&gt;**Affected Versions**  
- `@astrojs/cloudflare` ≤ 12.6.10 (and likely all previous versions)  
- Astro ≥ 4.x when used with `output: &amp;#39;server&amp;#39;` and the Cloudflare adapter&lt;/p&gt;
&lt;p&gt;**Root Cause – Vulnerable Code**  
File: `node_modules/@astrojs/internal-helpers/src/remote.ts`&lt;/p&gt;
&lt;p&gt;```ts
export function isRemoteAllowed(src: string, ...): boolean {
  if (!URL.canParse(src)) {
    return false;
  }
  const url = new URL(src);&lt;/p&gt;
&lt;p&gt;// Data URLs are always allowed 
  if (url.protocol === &amp;#39;data:&amp;#39;) {
    return true;
  }&lt;/p&gt;
&lt;p&gt;// Non-http(s) protocols are never allowed
  if (![&amp;#39;http:&amp;#39;, &amp;#39;https:&amp;#39;].includes(url.protocol)) {
    return false;
  }
  // ... further http/https allow-list checks
}
```&lt;/p&gt;
&lt;p&gt;In the **Cloudflare adapter**, the `/_image` endpoint contains logic similar to:&lt;/p&gt;
&lt;p&gt;```ts
	const href = ctx.url.searchPar…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: astro&lt;/p&gt;
&lt;p&gt;**Summary**  
A Cross-Site Scripting (XSS) vulnerability exists in Astro when using the **@astrojs/cloudflare** adapter with `output: &amp;#39;server&amp;#39;`. The built-in image optimization endpoint (`/_image`) uses `isRemoteAllowed()` from Astro’s internal helpers, which **unconditionally allows `data:` URLs**. When the endpoint receives a valid `data:` URL pointing to a malicious SVG containing JavaScript, and the Cloudflare-specific implementation performs a **302 redirect back to the original `data:` URL**, the browser directly executes the embedded JavaScript. This completely bypasses any domain allow-listing (`image.domains` / `image.remotePatterns`) and typical Content Security Policy mitigations.&lt;/p&gt;
&lt;p&gt;**Affected Versions**  
- `@astrojs/cloudflare` ≤ 12.6.10 (and likely all previous versions)  
- Astro ≥ 4.x when used with `output: &amp;#39;server&amp;#39;` and the Cloudflare adapter&lt;/p&gt;
&lt;p&gt;**Root Cause – Vulnerable Code**  
File: `node_modules/@astrojs/internal-helpers/src/remote.ts`&lt;/p&gt;
&lt;p&gt;```ts
export function isRemoteAllowed(src: string, ...): boolean {
  if (!URL.canParse(src)) {
    return false;
  }
  const url = new URL(src);&lt;/p&gt;
&lt;p&gt;// Data URLs are always allowed 
  if (url.protocol === &amp;#39;data:&amp;#39;) {
    return true;
  }&lt;/p&gt;
&lt;p&gt;// Non-http(s) protocols are never allowed
  if (![&amp;#39;http:&amp;#39;, &amp;#39;https:&amp;#39;].includes(url.protocol)) {
    return false;
  }
  // ... further http/https allow-list checks
}
```&lt;/p&gt;
&lt;p&gt;In the **Cloudflare adapter**, the `/_image` endpoint contains logic similar to:&lt;/p&gt;
&lt;p&gt;```ts
	const href = ctx.url.searchPar…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fvmw-cj7j-j39q</guid>
    </item>
  </channel>
</rss>
