{"id":"CVE-2025-64525","aliases":["GHSA-hr2q-hp5q-x767"],"url":"https://o3.security/vulnerability/CVE-2025-64525","summary":"Astro: URL manipulation via unsanitized headers leads to path-based middleware protections bypass, potential SSRF/cache-poisoning, CVE-2025-61925 bypass","details":"Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` and `x-forwarded-port` are insecurely used, without sanitization, to build the URL. This has several consequences, the most important of which are: middleware-based protected route bypass (only via `x-forwarded-proto`), DoS via cache poisoning (if a CDN is present), SSRF (only via `x-forwarded-proto`), URL pollution (potential SXSS, if a CDN is present), and WAF bypass. Version 5.15.5 contains a patch.","published":"2025-11-13T15:58:16.797Z","modified":"2026-08-08T03:47:57.295248878Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"astro","fixedVersion":"5.15.5"}],"fix":{"url":"https://github.com/withastro/astro/commit/dafbb1ba29912099c4faff1440033edc768af8b4","label":"withastro/astro@dafbb1b"},"references":[{"type":"WEB","url":"https://github.com/withastro/astro/blob/970ac0f51172e1e6bff4440516a851e725ac3097/packages/astro/src/core/app/node.ts#L121"},{"type":"WEB","url":"https://github.com/withastro/astro/blob/970ac0f51172e1e6bff4440516a851e725ac3097/packages/astro/src/core/app/node.ts#L97"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64525.json"},{"type":"ADVISORY","url":"https://github.com/withastro/astro/security/advisories/GHSA-hr2q-hp5q-x767"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64525"},{"type":"FIX","url":"https://github.com/withastro/astro/commit/dafbb1ba29912099c4faff1440033edc768af8b4"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:47:57.295248878Z"}}