{"id":"CVE-2026-33769","aliases":["GHSA-g735-7g2w-hh3f"],"url":"https://o3.security/vulnerability/CVE-2026-33769","summary":"Astro: Remote allowlist bypass via unanchored matchPathname wildcard","details":"Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path enforcement for remote URLs used by server-side fetchers such as the image optimization endpoint. The path matching logic for /* wildcards is unanchored, so a pathname that contains the allowed prefix later in the path can still match. As a result, an attacker can fetch paths outside the intended allowlisted prefix on an otherwise allowed host. This issue has been patched in version 5.18.1.","published":"2026-03-24T18:44:29.169Z","modified":"2026-08-07T11:31:10.717495211Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"astro","fixedVersion":"5.18.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33769.json"},{"type":"ADVISORY","url":"https://github.com/withastro/astro/security/advisories/GHSA-g735-7g2w-hh3f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33769"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:10.717495211Z"}}