Astro 0.18 lifecycle

Current status

standard supportlow

Astro 0.18 is currently in standard support.

Security: 15 tracked advisories affecting this line. Details below — lifecycle and vulnerability status are separate.

Official lifecycle source: Astro npm releases

Support phase
standard support
End of life
Not officially published
Latest release
0.18.1
Released
27 Jul 2021

At a glance

Version line
0.18
Initial release
27 Jul 2021
Lifecycle phase
standard support
Latest stable
0.18.1
Latest release date
27 Jul 2021
EOL
Not officially published
Risk
low
Releases tracked
14

Lifecycle timeline

Phases from published LifecyclePeriod records. Missing phases are not inferred.

  1. Release

    27 Jul 2021

  2. standard supportcurrent

    27 Jul 2021 → —

    Source: Astro npm releases

Astro 0.18 is currently in standard support.

Upgrade options

Newer supported Astro version lines from CompatHub lifecycle data. Compatibility and security context use existing evidence only.

You are on Astro 0.18

Supported

Supported upgrade options

Open full upgrade planner for Astro 0.18

Security

Advisories affecting Astro 0.18 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
15
Known exploited
0
Highest CVSS
7.5
  • CVE-2026-54299GHSA-2pvr-wf23-7pc7

    Astro: Host header SSRF in prerendered error page fetch

    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-20, CWE-918
    Affected:
    <6.4.6
    Fixed in:
    6.4.6
    Source:
    OSV source · Advisory
  • CVE-2026-50146GHSA-8hv8-536x-4wqp

    Astro: Reflected XSS via unescaped slot name

    CVSS:
    6.1 (moderate) · NVD
    CWE:
    CWE-80
    Affected:
    <6.3.3
    Fixed in:
    6.3.3
    Source:
    OSV source · Advisory
  • CVE-2026-59729GHSA-f48w-9m4c-m7f5

    Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)

    CVSS:
    5.1 (moderate) · NVD
    CWE:
    CWE-79
    Affected:
    <7.0.6
    Fixed in:
    7.0.6
    Source:
    OSV source · Advisory
  • CVE-2026-54298GHSA-jrpj-wcv7-9fh9

    Astro: XSS via Unescaped Attribute Names in Spread Props

    Affected:
    <6.4.6
    Fixed in:
    6.4.6
    Source:
    OSV source · Advisory
  • CVE-2026-45028GHSA-xr5h-phrj-8vxv

    Astro: Server island encrypted parameters vulnerable to cross-component replay

    Affected:
    <6.1.10
    Fixed in:
    6.1.10
    Source:
    OSV source · Advisory
  • CVE-2026-41067GHSA-j687-52p2-xcff

    Astro: XSS in define:vars via incomplete </script> tag sanitization

    Affected:
    <6.1.6
    Fixed in:
    6.1.6
    Source:
    OSV source · Advisory
  • CVE-2025-66202GHSA-whqg-ppgf-wp8c

    Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765

    Affected:
    <5.15.8
    Fixed in:
    5.15.8
    Source:
    OSV source · Advisory
  • CVE-2025-65019GHSA-fvmw-cj7j-j39q

    Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint

    Affected:
    <5.15.9
    Fixed in:
    5.15.9
    Source:
    OSV source · Advisory
  • CVE-2025-64765GHSA-ggxq-hp9w-j794

    Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values

    Affected:
    <5.15.8
    Fixed in:
    5.15.8
    Source:
    OSV source · Advisory
  • CVE-2025-64764GHSA-wrwg-2hg8-v723

    Astro vulnerable to reflected XSS via the server islands feature

    Affected:
    <5.15.8
    Fixed in:
    5.15.8
    Source:
    OSV source · Advisory
  • CVE-2025-64757GHSA-x3h8-62x9-952g

    Astro Development Server has Arbitrary Local File Read

    Affected:
    <5.14.3
    Fixed in:
    5.14.3
    Source:
    OSV source · Advisory
  • CVE-2025-61925GHSA-5ff5-9fcw-vg88

    Astro's `X-Forwarded-Host` is reflected without validation

    Affected:
    <5.14.3
    Fixed in:
    5.14.3
    Source:
    OSV source · Advisory
  • CVE-2025-55303GHSA-xf8x-j4p2-f749

    Astro allows unauthorized third-party images in _image endpoint

    Affected:
    <4.16.19
    Fixed in:
    4.16.19
    Source:
    OSV source · Advisory
  • CVE-2024-56159GHSA-49w6-73cw-chjr

    Astro's server source code is exposed to the public if sourcemaps are enabled

    Affected:
    <4.16.18
    Fixed in:
    4.16.18
    Source:
    OSV source · Advisory
  • CVE-2024-56140GHSA-c4pw-33h3-35xw

    Atro CSRF Middleware Bypass (security.checkOrigin)

    Affected:
    <4.16.17
    Fixed in:
    4.16.17
    Source:
    OSV source · Advisory

Latest release

0.18.1

Released 27 Jul 2021 · stable

https://registry.npmjs.org/astro/0.18.1

Previous releases

  • 0.18.2

    28 Jul 2021

  • 0.18.3

    28 Jul 2021

  • 0.18.0

    27 Jul 2021

Release history

14 concrete releases tracked for this line.

VersionRelease dateChannelSource
0.18.027 Jul 2021stableSource
0.18.127 Jul 2021stableSource
0.18.228 Jul 2021stableSource
0.18.328 Jul 2021stableSource
0.18.428 Jul 2021stableSource
0.18.530 Jul 2021stableSource
0.18.63 Aug 2021stableSource
0.18.73 Aug 2021stableSource
0.18.83 Aug 2021stableSource
0.18.95 Aug 2021stableSource
0.18.1011 Aug 2021stableSource
0.18.1111 Aug 2021stableSource
0.18.1211 Aug 2021stableSource
0.18.1313 Aug 2021stableSource

Release activity

Total releases
14
Last 30 days
0
Last 90 days
0
Avg. interval
~1 days
Most recent
27 Jul 2021

Should I use this version?

Suitable for new deployments

Astro 0.18 is currently supported (standard support).

Version comparison

Compact comparison against the nearest relevant release lines.

0.187
Statusstandard supportstandard support
Latest release0.18.07.2.8
EOLNot publishedNot published
Risklowlow

Sources

Where this information comes from.

Lifecycle sources

Release sources

Data coverage

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Releases tracked
14
Lifecycle periods
1
EOL
Not officially published
Provenance records
2
Data last checked
2 Sept 2026
Latest source update
2 Sept 2026

EOL: Not officially published

Other Astro versions