Astro 5 lifecycle
Current status
Astro 5 has no published vendor calendar support schedule in CompatHub's sources. Release history and dependency requirements are recorded from package metadata without inventing support commitments.
Security: 12 tracked advisories affecting this line. Details below — lifecycle and vulnerability status are separate.
Official lifecycle source: Astro npm releases
- Support phase
- unknown
- End of life
- Not officially published
- Latest release
- 5.18.2
- Released
- 26 May 2026
At a glance
- Version line
- 5
- Initial release
- 3 Dec 2024
- Lifecycle phase
- unknown
- Latest stable
- 5.18.2
- Latest release date
- 26 May 2026
- EOL
- Not officially published
- Risk
- medium
- Releases tracked
- 137
Lifecycle timeline
Phases from published LifecyclePeriod records. Missing phases are not inferred.
Release
3 Dec 2024
unknowncurrent
3 Dec 2024 → —
Source: Astro npm releases
Astro 5 has no published vendor calendar support schedule in CompatHub's sources. Release history and dependency requirements are recorded from package metadata without inventing support commitments.
Security
Advisories affecting Astro 5 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 12
- Known exploited
- 0
- Highest CVSS
- 7.5
- CVE-2026-54299GHSA-2pvr-wf23-7pc7
Astro: Host header SSRF in prerendered error page fetch
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-20, CWE-918
- Affected:
- <6.4.6
- Fixed in:
- 6.4.6
- Source:
- OSV source · Advisory
- CVE-2026-50146GHSA-8hv8-536x-4wqp
Astro: Reflected XSS via unescaped slot name
- CVSS:
- 6.1 (moderate) · NVD
- CWE:
- CWE-80
- Affected:
- <6.3.3
- Fixed in:
- 6.3.3
- Source:
- OSV source · Advisory
- CVE-2026-59729GHSA-f48w-9m4c-m7f5
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
- CVSS:
- 5.1 (moderate) · NVD
- CWE:
- CWE-79
- Affected:
- <7.0.6
- Fixed in:
- 7.0.6
- Source:
- OSV source · Advisory
- CVE-2026-54298GHSA-jrpj-wcv7-9fh9
Astro: XSS via Unescaped Attribute Names in Spread Props
- Affected:
- <6.4.6
- Fixed in:
- 6.4.6
- Source:
- OSV source · Advisory
- CVE-2026-45028GHSA-xr5h-phrj-8vxv
Astro: Server island encrypted parameters vulnerable to cross-component replay
- Affected:
- <6.1.10
- Fixed in:
- 6.1.10
- Source:
- OSV source · Advisory
- CVE-2026-41067GHSA-j687-52p2-xcff
Astro: XSS in define:vars via incomplete </script> tag sanitization
- Affected:
- <6.1.6
- Fixed in:
- 6.1.6
- Source:
- OSV source · Advisory
- CVE-2025-66202GHSA-whqg-ppgf-wp8c
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
- Affected:
- <5.15.8
- Fixed in:
- 5.15.8
- Source:
- OSV source · Advisory
- CVE-2025-65019GHSA-fvmw-cj7j-j39q
Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint
- Affected:
- <5.15.9
- Fixed in:
- 5.15.9
- Source:
- OSV source · Advisory
- CVE-2025-64765GHSA-ggxq-hp9w-j794
Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values
- Affected:
- <5.15.8
- Fixed in:
- 5.15.8
- Source:
- OSV source · Advisory
- CVE-2025-64764GHSA-wrwg-2hg8-v723
Astro vulnerable to reflected XSS via the server islands feature
- Affected:
- <5.15.8
- Fixed in:
- 5.15.8
- Source:
- OSV source · Advisory
- CVE-2025-64757GHSA-x3h8-62x9-952g
Astro Development Server has Arbitrary Local File Read
- Affected:
- <5.14.3
- Fixed in:
- 5.14.3
- Source:
- OSV source · Advisory
- CVE-2025-61925GHSA-5ff5-9fcw-vg88
Astro's `X-Forwarded-Host` is reflected without validation
- Affected:
- <5.14.3
- Fixed in:
- 5.14.3
- Source:
- OSV source · Advisory
Latest release
Previous releases
5.18.1
10 Mar 2026
5.18.0
25 Feb 2026
5.17.3
18 Feb 2026
Release history
137 concrete releases tracked for this line.
| Version | Release date | Channel | Source |
|---|---|---|---|
| 5.13.3 | 22 Aug 2025 | stable | Source |
| 5.13.2 | 15 Aug 2025 | stable | Source |
| 5.13.1 | 15 Aug 2025 | stable | Source |
| 5.13.0 | 14 Aug 2025 | stable | Source |
| 5.12.9 | 8 Aug 2025 | stable | Source |
| 5.12.8 | 1 Aug 2025 | stable | Source |
| 5.12.7 | 31 Jul 2025 | stable | Source |
| 5.12.6 | 30 Jul 2025 | stable | Source |
| 5.12.5 | 29 Jul 2025 | stable | Source |
| 5.12.4 | 28 Jul 2025 | stable | Source |
| 5.12.3 | 23 Jul 2025 | stable | Source |
| 5.12.2 | 22 Jul 2025 | stable | Source |
| 5.12.1 | 21 Jul 2025 | stable | Source |
| 5.12.0 | 17 Jul 2025 | stable | Source |
| 5.11.2 | 16 Jul 2025 | stable | Source |
| 5.11.1 | 14 Jul 2025 | stable | Source |
| 5.11.0 | 3 Jul 2025 | stable | Source |
| 5.10.2 | 1 Jul 2025 | stable | Source |
| 5.10.1 | 23 Jun 2025 | stable | Source |
| 5.10.0 | 19 Jun 2025 | stable | Source |
| 5.9.4 | 17 Jun 2025 | stable | Source |
| 5.9.3 | 13 Jun 2025 | stable | Source |
| 5.9.2 | 9 Jun 2025 | stable | Source |
| 5.9.1 | 7 Jun 2025 | stable | Source |
| 5.9.0 | 5 Jun 2025 | stable | Source |
Release activity
- Total releases
- 137
- Last 30 days
- 0
- Last 90 days
- 0
- Avg. interval
- ~6 days
- Most recent
- 26 May 2026
Should I use this version?
Lifecycle status unclear
Astro 5 has no published vendor calendar support schedule. CompatHub does not invent support commitments from release history alone.
Version comparison
Compact comparison against the nearest relevant release lines.
Compatibility
Evidence-backed compatibility results involving Astro 5. Only combinations CompatHub can evaluate from upstream sources are listed.
Compatible targets
Sources
Where this information comes from.
Lifecycle sources
- Astro npm releasesfirst party · high confidence
Official source: https://www.npmjs.com/package/astro
Last verified 2 Sept 2026
- OSV.devfirst party
Official source: https://osv.dev
Verification time not recorded
- NVD (NIST)first party
Official source: https://nvd.nist.gov
Verification time not recorded
- CISA Known Exploited Vulnerabilitiesfirst party
Official source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Verification time not recorded
Release sources
- Astro npm releasesfirst party · high confidence
Official source: https://www.npmjs.com/package/astro
Last verified 2 Sept 2026
Data coverage
Last checked = last successful upstream check. Latest source update = when upstream content last changed.
- Releases tracked
- 137
- Lifecycle periods
- 1
- EOL
- Not officially published
- Provenance records
- 2
- Data last checked
- 2 Sept 2026
- Latest source update
- 2 Sept 2026
EOL: Not officially published
