Package compatibility
Astro
Node.js requirements from npm Registry (engines.node) for the astro package. This is not a lifecycle software page.
Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.
Version lines
Each line reflects a declared engines.node tip. Requirement changes across tips appear as separate lines when present.
Known vulnerabilities
Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.
- CVE-2026-73423GHSA-8mv7-9c27-98vc
Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
- Affected:
- >=7.0.0,<7.0.6
- Fixed in:
- 7.0.6
- Source:
- OSV source
- CVE-2026-59729GHSA-f48w-9m4c-m7f5
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
- Affected:
- <7.0.6
- Fixed in:
- 7.0.6
- Source:
- OSV source · Advisory
- CVE-2026-59727GHSA-7pw4-f3q4-r2p2
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
- Affected:
- >=3.10.0,<7.0.4
- Fixed in:
- 7.0.4
- Source:
- OSV source · Advisory
- CVE-2026-59731GHSA-vj59-8hwv-xxmv
Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
- Affected:
- >=6.4.7,<6.4.8
- Fixed in:
- 6.4.8
- Source:
- OSV source · Advisory
- CVE-2026-73422GHSA-4g3v-8h47-v7g6
Astro: Reflected XSS via unescaped View Transition animation properties
- Affected:
- >=2.9.0,<7.1.0
- Fixed in:
- 7.1.0
- Source:
- OSV source
- CVE-2026-54298GHSA-jrpj-wcv7-9fh9
Astro: XSS via Unescaped Attribute Names in Spread Props
- Affected:
- <6.4.6
- Fixed in:
- 6.4.6
- Source:
- OSV source · Advisory
- CVE-2026-54299GHSA-2pvr-wf23-7pc7
Astro: Host header SSRF in prerendered error page fetch
- Affected:
- <6.4.6
- Fixed in:
- 6.4.6
- Source:
- OSV source · Advisory
- CVE-2026-50146GHSA-8hv8-536x-4wqp
Astro: Reflected XSS via unescaped slot name
- Affected:
- <6.3.3
- Fixed in:
- 6.3.3
- Source:
- OSV source · Advisory
- CVE-2026-45028GHSA-xr5h-phrj-8vxv
Astro: Server island encrypted parameters vulnerable to cross-component replay
- Affected:
- <6.1.10
- Fixed in:
- 6.1.10
- Source:
- OSV source · Advisory
- CVE-2026-41067GHSA-j687-52p2-xcff
Astro: XSS in define:vars via incomplete </script> tag sanitization
- Affected:
- <6.1.6
- Fixed in:
- 6.1.6
- Source:
- OSV source · Advisory
- CVE-2026-33769GHSA-g735-7g2w-hh3f
Astro: Remote allowlist bypass via unanchored matchPathname wildcard
- Affected:
- >=2.10.10,<5.18.1
- Fixed in:
- 5.18.1
- Source:
- OSV source · Advisory
- CVE-2025-66202GHSA-whqg-ppgf-wp8c
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
- Affected:
- <5.15.8
- Fixed in:
- 5.15.8
- Source:
- OSV source · Advisory
