Astro 4 lifecycle

Current status

unknownmedium

Astro 4 has no published vendor calendar support schedule in CompatHub's sources. Release history and dependency requirements are recorded from package metadata without inventing support commitments.

Security: 15 tracked advisories affecting this line. Details below — lifecycle and vulnerability status are separate.

Official lifecycle source: Astro npm releases

Support phase
unknown
End of life
Not officially published
Latest release
4.16.19
Released
19 Aug 2025

At a glance

Version line
4
Initial release
5 Dec 2023
Lifecycle phase
unknown
Latest stable
4.16.19
Latest release date
19 Aug 2025
EOL
Not officially published
Risk
medium
Releases tracked
145

Lifecycle timeline

Phases from published LifecyclePeriod records. Missing phases are not inferred.

  1. Release

    5 Dec 2023

  2. unknowncurrent

    5 Dec 2023 → —

    Source: Astro npm releases

Astro 4 has no published vendor calendar support schedule in CompatHub's sources. Release history and dependency requirements are recorded from package metadata without inventing support commitments.

Security

Advisories affecting Astro 4 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
15
Known exploited
0
Highest CVSS
7.5
  • CVE-2026-54299GHSA-2pvr-wf23-7pc7

    Astro: Host header SSRF in prerendered error page fetch

    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-20, CWE-918
    Affected:
    <6.4.6
    Fixed in:
    6.4.6
    Source:
    OSV source · Advisory
  • CVE-2026-50146GHSA-8hv8-536x-4wqp

    Astro: Reflected XSS via unescaped slot name

    CVSS:
    6.1 (moderate) · NVD
    CWE:
    CWE-80
    Affected:
    <6.3.3
    Fixed in:
    6.3.3
    Source:
    OSV source · Advisory
  • CVE-2026-59729GHSA-f48w-9m4c-m7f5

    Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)

    CVSS:
    5.1 (moderate) · NVD
    CWE:
    CWE-79
    Affected:
    <7.0.6
    Fixed in:
    7.0.6
    Source:
    OSV source · Advisory
  • CVE-2026-54298GHSA-jrpj-wcv7-9fh9

    Astro: XSS via Unescaped Attribute Names in Spread Props

    Affected:
    <6.4.6
    Fixed in:
    6.4.6
    Source:
    OSV source · Advisory
  • CVE-2026-45028GHSA-xr5h-phrj-8vxv

    Astro: Server island encrypted parameters vulnerable to cross-component replay

    Affected:
    <6.1.10
    Fixed in:
    6.1.10
    Source:
    OSV source · Advisory
  • CVE-2026-41067GHSA-j687-52p2-xcff

    Astro: XSS in define:vars via incomplete </script> tag sanitization

    Affected:
    <6.1.6
    Fixed in:
    6.1.6
    Source:
    OSV source · Advisory
  • CVE-2025-66202GHSA-whqg-ppgf-wp8c

    Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765

    Affected:
    <5.15.8
    Fixed in:
    5.15.8
    Source:
    OSV source · Advisory
  • CVE-2025-65019GHSA-fvmw-cj7j-j39q

    Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint

    Affected:
    <5.15.9
    Fixed in:
    5.15.9
    Source:
    OSV source · Advisory
  • CVE-2025-64765GHSA-ggxq-hp9w-j794

    Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values

    Affected:
    <5.15.8
    Fixed in:
    5.15.8
    Source:
    OSV source · Advisory
  • CVE-2025-64764GHSA-wrwg-2hg8-v723

    Astro vulnerable to reflected XSS via the server islands feature

    Affected:
    <5.15.8
    Fixed in:
    5.15.8
    Source:
    OSV source · Advisory
  • CVE-2025-64757GHSA-x3h8-62x9-952g

    Astro Development Server has Arbitrary Local File Read

    Affected:
    <5.14.3
    Fixed in:
    5.14.3
    Source:
    OSV source · Advisory
  • CVE-2025-61925GHSA-5ff5-9fcw-vg88

    Astro's `X-Forwarded-Host` is reflected without validation

    Affected:
    <5.14.3
    Fixed in:
    5.14.3
    Source:
    OSV source · Advisory
  • CVE-2025-55303GHSA-xf8x-j4p2-f749

    Astro allows unauthorized third-party images in _image endpoint

    Affected:
    <4.16.19
    Fixed in:
    4.16.19
    Source:
    OSV source · Advisory
  • CVE-2024-56159GHSA-49w6-73cw-chjr

    Astro's server source code is exposed to the public if sourcemaps are enabled

    Affected:
    <4.16.18
    Fixed in:
    4.16.18
    Source:
    OSV source · Advisory
  • CVE-2024-56140GHSA-c4pw-33h3-35xw

    Atro CSRF Middleware Bypass (security.checkOrigin)

    Affected:
    <4.16.17
    Fixed in:
    4.16.17
    Source:
    OSV source · Advisory

Latest release

4.16.19

Released 19 Aug 2025 · stable

https://registry.npmjs.org/astro/4.16.19

Previous releases

  • 4.16.18

    18 Dec 2024

  • 4.16.17

    5 Dec 2024

  • 4.16.16

    27 Nov 2024

Release history

145 concrete releases tracked for this line.

VersionRelease dateChannelSource
4.4.136 Mar 2024stableSource
4.4.126 Mar 2024stableSource
4.4.114 Mar 2024stableSource
4.4.104 Mar 2024stableSource
4.4.92 Mar 2024stableSource
4.4.81 Mar 2024stableSource
4.4.71 Mar 2024stableSource
4.4.628 Feb 2024stableSource
4.4.526 Feb 2024stableSource
4.4.423 Feb 2024stableSource
4.4.322 Feb 2024stableSource
4.4.221 Feb 2024stableSource
4.4.120 Feb 2024stableSource
4.4.015 Feb 2024stableSource
4.3.713 Feb 2024stableSource
4.3.612 Feb 2024stableSource
4.3.57 Feb 2024stableSource
4.3.47 Feb 2024stableSource
4.3.36 Feb 2024stableSource
4.3.22 Feb 2024stableSource
4.3.11 Feb 2024stableSource
4.3.01 Feb 2024stableSource
4.2.831 Jan 2024stableSource
4.2.730 Jan 2024stableSource
4.2.626 Jan 2024stableSource

Release activity

Total releases
145
Last 30 days
0
Last 90 days
0
Avg. interval
~9 days
Most recent
19 Aug 2025

Should I use this version?

Lifecycle status unclear

Astro 4 has no published vendor calendar support schedule. CompatHub does not invent support commitments from release history alone.

Version comparison

Compact comparison against the nearest relevant release lines.

45
Statusunknownunknown
Latest release4.16.195.18.2
EOLNot publishedNot published
Riskmediummedium

Compatibility

Evidence-backed compatibility results involving Astro 4. Only combinations CompatHub can evaluate from upstream sources are listed.

Open Compatibility Explorer →

Sources

Where this information comes from.

Lifecycle sources

Release sources

Data coverage

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Releases tracked
145
Lifecycle periods
1
EOL
Not officially published
Provenance records
2
Data last checked
2 Sept 2026
Latest source update
2 Sept 2026

EOL: Not officially published

Other Astro versions