<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 03:33:13 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-271304</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-271304</link>
      <description>EUVD-2026-271304</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-271304</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27829</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27829</link>
      <description>&lt;p&gt;Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in Astro&amp;#39;s image pipeline allows bypassing `image.domains` / `image.remotePatterns` restrictions, enabling the server to fetch content from unauthorized remote hosts. Astro provides an `inferSize` option that fetches remote images at render time to determine their dimensions. Remote image fetches are intended to be restricted to domains the site developer has manually authorized (using the `image.domains` or `image.remotePatterns` options). However, when `inferSize` is used, no domain validation is performed — the image is fetched from any host regardless of the configured restrictions. An attacker who can influence the image URL (e.g., via CMS content or user-supplied data) can cause the server to fetch from arbitrary hosts. This allows bypassing `image.domains` / `image.remotePatterns` restrictions to make server-side requests to unauthorized hosts. This includes the risk of server-side request forgery (SSRF) against internal network services and cloud metadata endpoints. Version 9.5.4 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in Astro&amp;#39;s image pipeline allows bypassing `image.domains` / `image.remotePatterns` restrictions, enabling the server to fetch content from unauthorized remote hosts. Astro provides an `inferSize` option that fetches remote images at render time to determine their dimensions. Remote image fetches are intended to be restricted to domains the site developer has manually authorized (using the `image.domains` or `image.remotePatterns` options). However, when `inferSize` is used, no domain validation is performed — the image is fetched from any host regardless of the configured restrictions. An attacker who can influence the image URL (e.g., via CMS content or user-supplied data) can cause the server to fetch from arbitrary hosts. This allows bypassing `image.domains` / `image.remotePatterns` restrictions to make server-side requests to unauthorized hosts. This includes the risk of server-side request forgery (SSRF) against internal network services and cloud metadata endpoints. Version 9.5.4 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27829</guid>
    </item>
    <item>
      <title>GHSA-cj9f-h6r6-4cx2 — Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cj9f-h6r6-4cx2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @astrojs/node&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A bug in Astro&amp;#39;s image pipeline allows bypassing `image.domains` / `image.remotePatterns` restrictions, enabling the server to fetch content from unauthorized remote hosts.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Astro provides an `inferSize` option that fetches remote images at render time to determine their dimensions. Remote image fetches are intended to be restricted to domains the site developer has manually authorized (using the `image.domains` or `image.remotePatterns` options).&lt;/p&gt;
&lt;p&gt;However, when `inferSize` is used, no domain validation is performed — the image is fetched from any host regardless of the configured restrictions. An attacker who can influence the image URL (e.g., via CMS content or user-supplied data) can cause the server to fetch from arbitrary hosts.&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;&lt;/p&gt;
&lt;p&gt;### Setup&lt;/p&gt;
&lt;p&gt;Create a new Astro project with the following files:&lt;/p&gt;
&lt;p&gt;`package.json`:
```json
{
  &amp;#34;name&amp;#34;: &amp;#34;poc-ssrf-infersize&amp;#34;,
  &amp;#34;private&amp;#34;: true,
  &amp;#34;scripts&amp;#34;: {
    &amp;#34;dev&amp;#34;: &amp;#34;astro dev --port 4322&amp;#34;,
    &amp;#34;build&amp;#34;: &amp;#34;astro build&amp;#34;
  },
  &amp;#34;dependencies&amp;#34;: {
    &amp;#34;astro&amp;#34;: &amp;#34;5.17.2&amp;#34;,
    &amp;#34;@astrojs/node&amp;#34;: &amp;#34;9.5.3&amp;#34;
  }
}
```&lt;/p&gt;
&lt;p&gt;`astro.config.mjs` — only `localhost:9000` is authorized:
```javascript
import { defineConfig } from &amp;#39;astro/config&amp;#39;;
import node from &amp;#39;@astrojs/node&amp;#39;;&lt;/p&gt;
&lt;p&gt;export default defineConfig({
  output: &amp;#39;server&amp;#39;,
  adapter: node({ mode: &amp;#39;standalone&amp;#39; }),
  image: {
    remotePatterns: [
      { hostname: &amp;#39;localhost&amp;#39;, port: &amp;#39;9000&amp;#39; }
    ]
  }
});
```&lt;/p&gt;
&lt;p&gt;`internal-service.mjs` — simulates an internal service on a no…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @astrojs/node&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A bug in Astro&amp;#39;s image pipeline allows bypassing `image.domains` / `image.remotePatterns` restrictions, enabling the server to fetch content from unauthorized remote hosts.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Astro provides an `inferSize` option that fetches remote images at render time to determine their dimensions. Remote image fetches are intended to be restricted to domains the site developer has manually authorized (using the `image.domains` or `image.remotePatterns` options).&lt;/p&gt;
&lt;p&gt;However, when `inferSize` is used, no domain validation is performed — the image is fetched from any host regardless of the configured restrictions. An attacker who can influence the image URL (e.g., via CMS content or user-supplied data) can cause the server to fetch from arbitrary hosts.&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;&lt;/p&gt;
&lt;p&gt;### Setup&lt;/p&gt;
&lt;p&gt;Create a new Astro project with the following files:&lt;/p&gt;
&lt;p&gt;`package.json`:
```json
{
  &amp;#34;name&amp;#34;: &amp;#34;poc-ssrf-infersize&amp;#34;,
  &amp;#34;private&amp;#34;: true,
  &amp;#34;scripts&amp;#34;: {
    &amp;#34;dev&amp;#34;: &amp;#34;astro dev --port 4322&amp;#34;,
    &amp;#34;build&amp;#34;: &amp;#34;astro build&amp;#34;
  },
  &amp;#34;dependencies&amp;#34;: {
    &amp;#34;astro&amp;#34;: &amp;#34;5.17.2&amp;#34;,
    &amp;#34;@astrojs/node&amp;#34;: &amp;#34;9.5.3&amp;#34;
  }
}
```&lt;/p&gt;
&lt;p&gt;`astro.config.mjs` — only `localhost:9000` is authorized:
```javascript
import { defineConfig } from &amp;#39;astro/config&amp;#39;;
import node from &amp;#39;@astrojs/node&amp;#39;;&lt;/p&gt;
&lt;p&gt;export default defineConfig({
  output: &amp;#39;server&amp;#39;,
  adapter: node({ mode: &amp;#39;standalone&amp;#39; }),
  image: {
    remotePatterns: [
      { hostname: &amp;#39;localhost&amp;#39;, port: &amp;#39;9000&amp;#39; }
    ]
  }
});
```&lt;/p&gt;
&lt;p&gt;`internal-service.mjs` — simulates an internal service on a no…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cj9f-h6r6-4cx2</guid>
    </item>
  </channel>
</rss>
