Astro 5 lifecycle
Current status
Astro 5 is currently in standard support.
Security: 12 tracked advisories affecting this line. Details below — lifecycle and vulnerability status are separate.
Official lifecycle source: Astro npm releases
- Support phase
- standard support
- End of life
- Not officially published
- Latest release
- 5.0.1
- Released
- 3 Dec 2024
At a glance
- Version line
- 5
- Initial release
- 3 Dec 2024
- Lifecycle phase
- standard support
- Latest stable
- 5.0.1
- Latest release date
- 3 Dec 2024
- EOL
- Not officially published
- Risk
- low
- Releases tracked
- 137
Lifecycle timeline
Phases from published LifecyclePeriod records. Missing phases are not inferred.
Release
3 Dec 2024
standard supportcurrent
3 Dec 2024 → —
Source: Astro npm releases
Astro 5 is currently in standard support.
Upgrade options
Newer supported Astro version lines from CompatHub lifecycle data. Compatibility and security context use existing evidence only.
You are on Astro 5
Supported
Supported upgrade options
- Astro 7Upgrade planner →Supported· 2 major versions newer
- Astro 6Upgrade planner →Supported· 1 major version newer
Security
Advisories affecting Astro 5 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 12
- Known exploited
- 0
- Highest CVSS
- 7.5
- CVE-2026-54299GHSA-2pvr-wf23-7pc7
Astro: Host header SSRF in prerendered error page fetch
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-20, CWE-918
- Affected:
- <6.4.6
- Fixed in:
- 6.4.6
- Source:
- OSV source · Advisory
- CVE-2026-50146GHSA-8hv8-536x-4wqp
Astro: Reflected XSS via unescaped slot name
- CVSS:
- 6.1 (moderate) · NVD
- CWE:
- CWE-80
- Affected:
- <6.3.3
- Fixed in:
- 6.3.3
- Source:
- OSV source · Advisory
- CVE-2026-59729GHSA-f48w-9m4c-m7f5
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
- CVSS:
- 5.1 (moderate) · NVD
- CWE:
- CWE-79
- Affected:
- <7.0.6
- Fixed in:
- 7.0.6
- Source:
- OSV source · Advisory
- CVE-2026-54298GHSA-jrpj-wcv7-9fh9
Astro: XSS via Unescaped Attribute Names in Spread Props
- Affected:
- <6.4.6
- Fixed in:
- 6.4.6
- Source:
- OSV source · Advisory
- CVE-2026-45028GHSA-xr5h-phrj-8vxv
Astro: Server island encrypted parameters vulnerable to cross-component replay
- Affected:
- <6.1.10
- Fixed in:
- 6.1.10
- Source:
- OSV source · Advisory
- CVE-2026-41067GHSA-j687-52p2-xcff
Astro: XSS in define:vars via incomplete </script> tag sanitization
- Affected:
- <6.1.6
- Fixed in:
- 6.1.6
- Source:
- OSV source · Advisory
- CVE-2025-66202GHSA-whqg-ppgf-wp8c
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
- Affected:
- <5.15.8
- Fixed in:
- 5.15.8
- Source:
- OSV source · Advisory
- CVE-2025-65019GHSA-fvmw-cj7j-j39q
Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint
- Affected:
- <5.15.9
- Fixed in:
- 5.15.9
- Source:
- OSV source · Advisory
- CVE-2025-64765GHSA-ggxq-hp9w-j794
Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values
- Affected:
- <5.15.8
- Fixed in:
- 5.15.8
- Source:
- OSV source · Advisory
- CVE-2025-64764GHSA-wrwg-2hg8-v723
Astro vulnerable to reflected XSS via the server islands feature
- Affected:
- <5.15.8
- Fixed in:
- 5.15.8
- Source:
- OSV source · Advisory
- CVE-2025-64757GHSA-x3h8-62x9-952g
Astro Development Server has Arbitrary Local File Read
- Affected:
- <5.14.3
- Fixed in:
- 5.14.3
- Source:
- OSV source · Advisory
- CVE-2025-61925GHSA-5ff5-9fcw-vg88
Astro's `X-Forwarded-Host` is reflected without validation
- Affected:
- <5.14.3
- Fixed in:
- 5.14.3
- Source:
- OSV source · Advisory
Latest release
Previous releases
5.0.2
3 Dec 2024
5.0.3
5 Dec 2024
5.0.0
3 Dec 2024
Release history
137 concrete releases tracked for this line.
| Version | Release date | Channel | Source |
|---|---|---|---|
| 5.0.1 | 3 Dec 2024 | stable | Source |
| 5.0.2 | 3 Dec 2024 | stable | Source |
| 5.0.3 | 5 Dec 2024 | stable | Source |
| 5.0.4 | 9 Dec 2024 | stable | Source |
| 5.0.5 | 11 Dec 2024 | stable | Source |
| 5.0.6 | 16 Dec 2024 | stable | Source |
| 5.0.7 | 16 Dec 2024 | stable | Source |
| 5.0.8 | 16 Dec 2024 | stable | Source |
| 5.0.9 | 17 Dec 2024 | stable | Source |
| 5.1.0 | 19 Dec 2024 | stable | Source |
| 5.1.1 | 20 Dec 2024 | stable | Source |
| 5.1.2 | 2 Jan 2025 | stable | Source |
| 5.1.3 | 6 Jan 2025 | stable | Source |
| 5.1.4 | 9 Jan 2025 | stable | Source |
| 5.1.5 | 10 Jan 2025 | stable | Source |
| 5.1.6 | 13 Jan 2025 | stable | Source |
| 5.1.7 | 15 Jan 2025 | stable | Source |
| 5.1.8 | 20 Jan 2025 | stable | Source |
| 5.1.9 | 23 Jan 2025 | stable | Source |
| 5.1.10 | 27 Jan 2025 | stable | Source |
| 5.2.0 | 30 Jan 2025 | stable | Source |
| 5.2.1 | 30 Jan 2025 | stable | Source |
| 5.2.2 | 31 Jan 2025 | stable | Source |
| 5.2.3 | 31 Jan 2025 | stable | Source |
| 5.0.0 | 3 Dec 2024 | stable | Source |
Release activity
- Total releases
- 137
- Last 30 days
- 0
- Last 90 days
- 0
- Avg. interval
- ~6 days
- Most recent
- 3 Dec 2024
Should I use this version?
Suitable for new deployments
Astro 5 is currently supported (standard support).
Version comparison
Compact comparison against the nearest relevant release lines.
Compatibility
Evidence-backed compatibility results involving Astro 5. Only combinations CompatHub can evaluate from upstream sources are listed.
Compatible targets
Sources
Where this information comes from.
Lifecycle sources
- Astro npm releasesfirst party · high confidence
Official source: https://www.npmjs.com/package/astro
Last verified 2 Sept 2026
- OSV.devfirst party
Official source: https://osv.dev
Verification time not recorded
- NVD (NIST)first party
Official source: https://nvd.nist.gov
Verification time not recorded
- CISA Known Exploited Vulnerabilitiesfirst party
Official source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Verification time not recorded
Release sources
- Astro npm releasesfirst party · high confidence
Official source: https://www.npmjs.com/package/astro
Last verified 2 Sept 2026
Data coverage
Last checked = last successful upstream check. Latest source update = when upstream content last changed.
- Releases tracked
- 137
- Lifecycle periods
- 1
- EOL
- Not officially published
- Provenance records
- 2
- Data last checked
- 2 Sept 2026
- Latest source update
- 2 Sept 2026
EOL: Not officially published
