Executive brief
Astro is a web framework used to build server-rendered web applications. The framework insecurely processes HTTP headers (x-forwarded-proto and x-forwarded-port) without sanitization, allowing attackers to manipulate request URLs. An attacker can bypass authentication middleware, trigger cache poisoning attacks on CDN-backed sites, perform server-side request forgery, or poison WAF rules—all without authentication.
Technical details
The vulnerability is an improper input validation flaw in Astro's createRequest() function (packages/astro/src/core/app/node.ts, lines 97 and 121), which directly uses x-forwarded-proto and x-forwarded-port headers without sanitization to construct request URLs via the URL constructor. An unauthenticated attacker on the network can inject malicious header values to rewrite the entire URL including protocol, host, port, and path; for example, setting x-forwarded-proto to "https://malicious-url.com/?tank=" causes the URL to be constructed as "https://malicious-url.com/?tank=://localhost/ssr". This enables multiple attack vectors: path-based middleware checks can be bypassed by manipulating the pathname (e.g., "admin" vs "/admin"), SSRF attacks are possible if the constructed URL is used in downstream API calls, and cache-poisoning DoS attacks can be triggered on CDN-backed applications by forcing 404 responses to be cached. The vulnerability affects all on-demand rendered pages (all non-static routes), and patches are available in Astro 5.15.5 and later.
Affected products
- Astro Astro <= 2.16.0
Timeline
- 2025-11-13: disclosed
- 2025-11-13: patched: patched in version >= 5.15.5