Astro 4 lifecycle
Current status
Astro 4 has no published vendor calendar support schedule in CompatHub's sources. Release history and dependency requirements are recorded from package metadata without inventing support commitments.
Security: 15 tracked advisories affecting this line. Details below — lifecycle and vulnerability status are separate.
Official lifecycle source: Astro npm releases
- Support phase
- unknown
- End of life
- Not officially published
- Latest release
- 4.16.19
- Released
- 19 Aug 2025
At a glance
- Version line
- 4
- Initial release
- 5 Dec 2023
- Lifecycle phase
- unknown
- Latest stable
- 4.16.19
- Latest release date
- 19 Aug 2025
- EOL
- Not officially published
- Risk
- medium
- Releases tracked
- 145
Lifecycle timeline
Phases from published LifecyclePeriod records. Missing phases are not inferred.
Release
5 Dec 2023
unknowncurrent
5 Dec 2023 → —
Source: Astro npm releases
Astro 4 has no published vendor calendar support schedule in CompatHub's sources. Release history and dependency requirements are recorded from package metadata without inventing support commitments.
Security
Advisories affecting Astro 4 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 15
- Known exploited
- 0
- Highest CVSS
- 7.5
- CVE-2026-54299GHSA-2pvr-wf23-7pc7
Astro: Host header SSRF in prerendered error page fetch
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-20, CWE-918
- Affected:
- <6.4.6
- Fixed in:
- 6.4.6
- Source:
- OSV source · Advisory
- CVE-2026-50146GHSA-8hv8-536x-4wqp
Astro: Reflected XSS via unescaped slot name
- CVSS:
- 6.1 (moderate) · NVD
- CWE:
- CWE-80
- Affected:
- <6.3.3
- Fixed in:
- 6.3.3
- Source:
- OSV source · Advisory
- CVE-2026-59729GHSA-f48w-9m4c-m7f5
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
- CVSS:
- 5.1 (moderate) · NVD
- CWE:
- CWE-79
- Affected:
- <7.0.6
- Fixed in:
- 7.0.6
- Source:
- OSV source · Advisory
- CVE-2026-54298GHSA-jrpj-wcv7-9fh9
Astro: XSS via Unescaped Attribute Names in Spread Props
- Affected:
- <6.4.6
- Fixed in:
- 6.4.6
- Source:
- OSV source · Advisory
- CVE-2026-45028GHSA-xr5h-phrj-8vxv
Astro: Server island encrypted parameters vulnerable to cross-component replay
- Affected:
- <6.1.10
- Fixed in:
- 6.1.10
- Source:
- OSV source · Advisory
- CVE-2026-41067GHSA-j687-52p2-xcff
Astro: XSS in define:vars via incomplete </script> tag sanitization
- Affected:
- <6.1.6
- Fixed in:
- 6.1.6
- Source:
- OSV source · Advisory
- CVE-2025-66202GHSA-whqg-ppgf-wp8c
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
- Affected:
- <5.15.8
- Fixed in:
- 5.15.8
- Source:
- OSV source · Advisory
- CVE-2025-65019GHSA-fvmw-cj7j-j39q
Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint
- Affected:
- <5.15.9
- Fixed in:
- 5.15.9
- Source:
- OSV source · Advisory
- CVE-2025-64765GHSA-ggxq-hp9w-j794
Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values
- Affected:
- <5.15.8
- Fixed in:
- 5.15.8
- Source:
- OSV source · Advisory
- CVE-2025-64764GHSA-wrwg-2hg8-v723
Astro vulnerable to reflected XSS via the server islands feature
- Affected:
- <5.15.8
- Fixed in:
- 5.15.8
- Source:
- OSV source · Advisory
- CVE-2025-64757GHSA-x3h8-62x9-952g
Astro Development Server has Arbitrary Local File Read
- Affected:
- <5.14.3
- Fixed in:
- 5.14.3
- Source:
- OSV source · Advisory
- CVE-2025-61925GHSA-5ff5-9fcw-vg88
Astro's `X-Forwarded-Host` is reflected without validation
- Affected:
- <5.14.3
- Fixed in:
- 5.14.3
- Source:
- OSV source · Advisory
- CVE-2025-55303GHSA-xf8x-j4p2-f749
Astro allows unauthorized third-party images in _image endpoint
- Affected:
- <4.16.19
- Fixed in:
- 4.16.19
- Source:
- OSV source · Advisory
- CVE-2024-56159GHSA-49w6-73cw-chjr
Astro's server source code is exposed to the public if sourcemaps are enabled
- Affected:
- <4.16.18
- Fixed in:
- 4.16.18
- Source:
- OSV source · Advisory
- CVE-2024-56140GHSA-c4pw-33h3-35xw
Atro CSRF Middleware Bypass (security.checkOrigin)
- Affected:
- <4.16.17
- Fixed in:
- 4.16.17
- Source:
- OSV source · Advisory
Latest release
Previous releases
4.16.18
18 Dec 2024
4.16.17
5 Dec 2024
4.16.16
27 Nov 2024
Release history
145 concrete releases tracked for this line.
| Version | Release date | Channel | Source |
|---|---|---|---|
| 4.15.7 | 17 Sept 2024 | stable | Source |
| 4.15.6 | 13 Sept 2024 | stable | Source |
| 4.15.5 | 13 Sept 2024 | stable | Source |
| 4.15.4 | 6 Sept 2024 | stable | Source |
| 4.15.3 | 5 Sept 2024 | stable | Source |
| 4.15.2 | 2 Sept 2024 | stable | Source |
| 4.15.1 | 29 Aug 2024 | stable | Source |
| 4.15.0 | 29 Aug 2024 | stable | Source |
| 4.14.6 | 28 Aug 2024 | stable | Source |
| 4.14.5 | 22 Aug 2024 | stable | Source |
| 4.14.4 | 21 Aug 2024 | stable | Source |
| 4.14.3 | 20 Aug 2024 | stable | Source |
| 4.14.2 | 15 Aug 2024 | stable | Source |
| 4.14.1 | 15 Aug 2024 | stable | Source |
| 4.14.0 | 15 Aug 2024 | stable | Source |
| 4.13.4 | 14 Aug 2024 | stable | Source |
| 4.13.3 | 9 Aug 2024 | stable | Source |
| 4.13.2 | 8 Aug 2024 | stable | Source |
| 4.13.1 | 2 Aug 2024 | stable | Source |
| 4.13.0 | 1 Aug 2024 | stable | Source |
| 4.12.3 | 30 Jul 2024 | stable | Source |
| 4.12.2 | 19 Jul 2024 | stable | Source |
| 4.12.1 | 18 Jul 2024 | stable | Source |
| 4.12.0 | 18 Jul 2024 | stable | Source |
| 4.11.6 | 17 Jul 2024 | stable | Source |
Release activity
- Total releases
- 145
- Last 30 days
- 0
- Last 90 days
- 0
- Avg. interval
- ~9 days
- Most recent
- 19 Aug 2025
Should I use this version?
Lifecycle status unclear
Astro 4 has no published vendor calendar support schedule. CompatHub does not invent support commitments from release history alone.
Version comparison
Compact comparison against the nearest relevant release lines.
Compatibility
Evidence-backed compatibility results involving Astro 4. Only combinations CompatHub can evaluate from upstream sources are listed.
Compatible targets
Sources
Where this information comes from.
Lifecycle sources
- Astro npm releasesfirst party · high confidence
Official source: https://www.npmjs.com/package/astro
Last verified 2 Sept 2026
- OSV.devfirst party
Official source: https://osv.dev
Verification time not recorded
- NVD (NIST)first party
Official source: https://nvd.nist.gov
Verification time not recorded
- CISA Known Exploited Vulnerabilitiesfirst party
Official source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Verification time not recorded
Release sources
- Astro npm releasesfirst party · high confidence
Official source: https://www.npmjs.com/package/astro
Last verified 2 Sept 2026
Data coverage
Last checked = last successful upstream check. Latest source update = when upstream content last changed.
- Releases tracked
- 145
- Lifecycle periods
- 1
- EOL
- Not officially published
- Provenance records
- 2
- Data last checked
- 2 Sept 2026
- Latest source update
- 2 Sept 2026
EOL: Not officially published
