AI description
CVE-2025-64525 affects the Astro web framework in versions 2.16.0 up to, but excluding, 5.15.5 when utilizing on-demand rendering. The vulnerability stems from the insecure use of the `x-forwarded-proto` and `x-forwarded-port` request headers without proper sanitization when constructing the URL. This insecure URL construction can lead to several consequences, including bypassing middleware-protected routes (only via `x-forwarded-proto`), denial-of-service (DoS) via cache poisoning (if a CDN is present), server-side request forgery (SSRF) (only via `x-forwarded-proto`), URL pollution potentially leading to cross-site scripting (SXSS) (if a CDN is present), and web application firewall (WAF) bypass. A patch is available in version 5.15.5.
- Description
- Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` and `x-forwarded-port` are insecurely used, without sanitization, to build the URL. This has several consequences, the most important of which are: middleware-based protected route bypass (only via `x-forwarded-proto`), DoS via cache poisoning (if a CDN is present), SSRF (only via `x-forwarded-proto`), URL pollution (potential SXSS, if a CDN is present), and WAF bypass. Version 5.15.5 contains a patch.
- Source
- security-advisories@github.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 6.5
- Impact score
- 2.5
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- Severity
- MEDIUM
- security-advisories@github.com
- CWE-918
- Hype score
- Not currently trending
CVE-2025-64525 Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` and `x-forwarded-p… https://t.co/O78fRq1h6u
@CVEnew
13 Nov 2025
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
release of our new paper (w/ @inzo____) which resulted in CVE-2025-64525: Astro framework and standards weaponization from path-based middleware protection bypass to potential SSRF & XSS + full bypass of CVE-2025-61925 on @astrodotbuild https://t.co/xTO55gNFu4 https://t.co
@zhero___
13 Nov 2025
7266 Impressions
45 Retweets
170 Likes
72 Bookmarks
7 Replies
3 Quotes