CVE-2025-64525
CVE-2025-64525 is a medium-severity vulnerability in Astro with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-918.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- EPSS exploit prediction: 1% (65th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-175298
- Weakness: CWE-918
- Affected product: Astro
- Published:
- Last modified:
Description
Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` and `x-forwarded-port` are insecurely used, without sanitization, to build the URL. This has several consequences, the most important of which are: middleware-based protected route bypass (only via `x-forwarded-proto`), DoS via cache poisoning (if a CDN is present), SSRF (only via `x-forwarded-proto`), URL pollution (potential SXSS, if a CDN is present), and WAF bypass. Version 5.15.5 contains a patch.
Frequently asked questions
- What is CVE-2025-64525?
- Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` and `x-forwarded-port` are insecurely used, without sanitization, to build the URL. This has several consequences, the most important of which are: middleware-based protected route bypass (only via `x-forwarded-proto`), DoS via cache poisoning (if a CDN is present), SSRF (only via `x-forwarded-proto`), URL pollution (potential SXSS, if a CDN is present), and WAF bypass. Version 5.15.5 contains a patch.
- How severe is CVE-2025-64525?
- CVE-2025-64525 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability low.
- Is CVE-2025-64525 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (65th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-64525?
- CVE-2025-64525 affects Astro. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-64525?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-64525 have an EU (EUVD) identifier?
- Yes. CVE-2025-64525 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-175298.
- When was CVE-2025-64525 published?
- CVE-2025-64525 was published on 2025-11-13 and last updated on 2026-06-17.
References
- https://github.com/withastro/astro/blob/970ac0f51172e1e6bff4440516a851e725ac3097/packages/astro/src/core/app/node.ts#L121
- https://github.com/withastro/astro/blob/970ac0f51172e1e6bff4440516a851e725ac3097/packages/astro/src/core/app/node.ts#L97
- https://github.com/withastro/astro/commit/dafbb1ba29912099c4faff1440033edc768af8b4
- https://github.com/withastro/astro/security/advisories/GHSA-hr2q-hp5q-x767
Affected products (1)
- cpe:2.3:a:astro:astro:*:*:*:*:*:node.js:*:*
More vulnerabilities in Astro
- CVE-2026-54299 — High (CVSS 7.5): Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const…
- CVE-2025-59837 — High (CVSS 7.2): Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy…
- CVE-2026-50146 — High (CVSS 7.1): Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content…
- CVE-2025-64764 — High (CVSS 7.1): Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands…
- CVE-2025-66202 — Medium (CVSS 6.5): Astro is a web framework. Versions 5.15.7 and below have a double URL encoding bypass which allows any unauthenticated…
- CVE-2025-61925 — Medium (CVSS 6.5): Astro is a web framework. Prior to version 5.14.2, Astro reflects the value in `X-Forwarded-Host` in output when using…
Other CWE-918 (Server-Side Request Forgery (SSRF)) vulnerabilities
- CVE-2026-69502 — Critical (CVSS 10.0): Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a…
- CVE-2026-65801 — Critical (CVSS 10.0): Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges…
- CVE-2026-48331 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in…
- CVE-2026-54735 — Critical (CVSS 10.0): Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version…
- CVE-2026-57106 — Critical (CVSS 10.0): Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-15409 — Critical (CVSS 10.0): A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A…
Browse all CWE-918 (Server-Side Request Forgery (SSRF)) vulnerabilities →