CVE-2026-33768
CVE-2026-33768 is a medium-severity vulnerability in Astro @astrojs/vercel with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-441.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- EPSS exploit prediction: 0% (26th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-14982
- Weakness: CWE-441
- Affected product: Astro @astrojs/vercel
- Published:
- Last modified:
Description
Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path header and x_astro_path query parameter to rewrite the internal request path, with no authentication whatsoever. On deployments without Edge Middleware, this lets anyone bypass Vercel's platform-level path restrictions entirely. The override preserves the original HTTP method and body, so this isn't limited to GET. POST, PUT, DELETE all land on the rewritten path. A Firewall rule blocking /admin/* does nothing when the request comes in as POST /api/health?x_astro_path=/admin/delete-user. This issue has been patched in version 10.0.2.
Frequently asked questions
- What is CVE-2026-33768?
- Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path header and x_astro_path query parameter to rewrite the internal request path, with no authentication whatsoever. On deployments without Edge Middleware, this lets anyone bypass Vercel's platform-level path restrictions entirely. The override preserves the original HTTP method and body, so this isn't limited to GET. POST, PUT, DELETE all land on the rewritten path. A Firewall rule blocking /admin/* does nothing when the request comes in as POST /api/health?x_astro_path=/admin/delete-user. This issue has been patched in version 10.0.2.
- How severe is CVE-2026-33768?
- CVE-2026-33768 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability none.
- Is CVE-2026-33768 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (26th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-33768?
- CVE-2026-33768 affects Astro @astrojs/vercel. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-33768?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-33768 have an EU (EUVD) identifier?
- Yes. CVE-2026-33768 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-14982.
- When was CVE-2026-33768 published?
- CVE-2026-33768 was published on 2026-03-24 and last updated on 2026-06-17.
References
- https://github.com/withastro/astro/commit/335a204161f5a7293c128db570901d4f8639c6ed
- https://github.com/withastro/astro/pull/15959
- https://github.com/withastro/astro/releases/tag/%40astrojs%2Fvercel%4010.0.2
- https://github.com/withastro/astro/security/advisories/GHSA-mr6q-rp88-fx84
Affected products (1)
- cpe:2.3:a:astro:\@astrojs\/vercel:*:*:*:*:*:*:*:*
Other CWE-441 vulnerabilities
- CVE-2026-69399 — Critical (CVSS 10.0): Azure Arc Elevation of Privilege Vulnerability
- CVE-2026-83548 — Critical (CVSS 10.0): A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended…
- CVE-2026-42933 — Critical (CVSS 10.0): Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow…
- CVE-2026-39906 — Critical (CVSS 10.0): Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel…
- CVE-2026-67567 — Critical (CVSS 9.9): A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the…
- CVE-2026-72526 — Critical (CVSS 9.9): A flaw was found in the multicloud-integrations component. The Application propagation controller processes the…