CVE-2026-102983
CVE-2026-102983 is a medium-severity vulnerability with a CVSS 4.0 base score of 6.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-625.
Key facts
- Severity: Medium (CVSS 4.0 base score 6.3)
- EPSS exploit prediction: 0% (22nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-625
- Published:
- Last modified:
Description
Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL. Because Netlify evaluates these expressions with RegExp.test(), an allowed origin appearing only in a source URL's path or query can satisfy image.domains or image.remotePatterns while the URL's actual host remains attacker-controlled. An unauthenticated request to the public /.netlify/images endpoint can therefore cause the Image CDN to request attacker-selected URLs and may probe or reach internal services. Netlify egress protections may constrain reachable targets, and image transformation limits direct response exfiltration; no confidentiality or integrity impact has been demonstrated. This issue is fixed in version 8.2.4.
Frequently asked questions
- What is CVE-2026-102983?
- Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL. Because Netlify evaluates these expressions with RegExp.test(), an allowed origin appearing only in a source URL's path or query can satisfy image.domains or image.remotePatterns while the URL's actual host remains attacker-controlled. An unauthenticated request to the public /.netlify/images endpoint can therefore cause the Image CDN to request attacker-selected URLs and may probe or reach internal services. Netlify egress protections may constrain reachable targets, and image transformation limits direct response exfiltration; no confidentiality or integrity impact has been demonstrated. This issue is fixed in version 8.2.4.
- How severe is CVE-2026-102983?
- CVE-2026-102983 has a CVSS 4.0 base score of 6.3, rated medium severity.
- Is CVE-2026-102983 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (22nd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-102983?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-102983 published?
- CVE-2026-102983 was published on 2026-09-30.
References
- https://github.com/withastro/astro/commit/e362d4cf540b27730482455c8fc02efe57d16702
- https://github.com/withastro/astro/pull/17752
- https://github.com/withastro/astro/releases/tag/@astrojs/[email protected]
- https://github.com/withastro/astro/security/advisories/GHSA-4233-jc72-56c5
Other CWE-625 vulnerabilities
- CVE-2026-32973 — Critical (CVSS 9.8): OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly…
- CVE-2018-8926 — High (CVSS 8.8): Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and…
- CVE-2026-64940 — High (CVSS 8.6): Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular…
- CVE-2026-19278 — Medium (CVSS 6.8): A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator…
- CVE-2026-23651 — Medium (CVSS 6.7): Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
- CVE-2020-8910 — Medium (CVSS 6.5): A URL parsing issue in goog.uri of the Google Closure Library versions up to and including v20200224 allows an attacker…