Package compatibility

Astro 3

What Node.js versions does this Astro version support?

Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.

Declared Node.js requirement

engines.node
>=18.14.1
Tip version
3.6.5
Source
npm Registry (engines.node)

Node.js compatibility matrix

Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.

Other Astro lines

Security

Advisories affecting Astro 3 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
15
Known exploited
0
Highest CVSS
  • CVE-2026-59729GHSA-f48w-9m4c-m7f5

    Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)

    Affected:
    <7.0.6
    Fixed in:
    7.0.6
    Source:
    OSV source · Advisory
  • CVE-2026-54298GHSA-jrpj-wcv7-9fh9

    Astro: XSS via Unescaped Attribute Names in Spread Props

    Affected:
    <6.4.6
    Fixed in:
    6.4.6
    Source:
    OSV source · Advisory
  • CVE-2026-54299GHSA-2pvr-wf23-7pc7

    Astro: Host header SSRF in prerendered error page fetch

    Affected:
    <6.4.6
    Fixed in:
    6.4.6
    Source:
    OSV source · Advisory
  • CVE-2026-50146GHSA-8hv8-536x-4wqp

    Astro: Reflected XSS via unescaped slot name

    Affected:
    <6.3.3
    Fixed in:
    6.3.3
    Source:
    OSV source · Advisory
  • CVE-2026-45028GHSA-xr5h-phrj-8vxv

    Astro: Server island encrypted parameters vulnerable to cross-component replay

    Affected:
    <6.1.10
    Fixed in:
    6.1.10
    Source:
    OSV source · Advisory
  • CVE-2026-41067GHSA-j687-52p2-xcff

    Astro: XSS in define:vars via incomplete </script> tag sanitization

    Affected:
    <6.1.6
    Fixed in:
    6.1.6
    Source:
    OSV source · Advisory
  • CVE-2025-66202GHSA-whqg-ppgf-wp8c

    Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765

    Affected:
    <5.15.8
    Fixed in:
    5.15.8
    Source:
    OSV source · Advisory
  • CVE-2025-65019GHSA-fvmw-cj7j-j39q

    Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint

    Affected:
    <5.15.9
    Fixed in:
    5.15.9
    Source:
    OSV source · Advisory
  • CVE-2025-64765GHSA-ggxq-hp9w-j794

    Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values

    Affected:
    <5.15.8
    Fixed in:
    5.15.8
    Source:
    OSV source · Advisory
  • CVE-2025-64764GHSA-wrwg-2hg8-v723

    Astro vulnerable to reflected XSS via the server islands feature

    Affected:
    <5.15.8
    Fixed in:
    5.15.8
    Source:
    OSV source · Advisory
  • CVE-2025-64757GHSA-x3h8-62x9-952g

    Astro Development Server has Arbitrary Local File Read

    Affected:
    <5.14.3
    Fixed in:
    5.14.3
    Source:
    OSV source · Advisory
  • CVE-2025-61925GHSA-5ff5-9fcw-vg88

    Astro's `X-Forwarded-Host` is reflected without validation

    Affected:
    <5.14.3
    Fixed in:
    5.14.3
    Source:
    OSV source · Advisory
  • CVE-2025-55303GHSA-xf8x-j4p2-f749

    Astro allows unauthorized third-party images in _image endpoint

    Affected:
    <4.16.19
    Fixed in:
    4.16.19
    Source:
    OSV source · Advisory
  • CVE-2024-56159GHSA-49w6-73cw-chjr

    Astro's server source code is exposed to the public if sourcemaps are enabled

    Affected:
    <4.16.18
    Fixed in:
    4.16.18
    Source:
    OSV source · Advisory
  • CVE-2024-56140GHSA-c4pw-33h3-35xw

    Atro CSRF Middleware Bypass (security.checkOrigin)

    Affected:
    <4.16.17
    Fixed in:
    4.16.17
    Source:
    OSV source · Advisory