8 Total advisories
8 Vulnerabilities
0 Malware
Dependency scanning
Check whether @astrojs/node is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-59730
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
MEDIUM 5.3
CVE-2026-41322
Astro: Cache Poisoning due to incorrect error handling when if-match header is malformed
HIGH 8.6
CVE-2026-25545
Astro has Full-Read SSRF in error rendering via Host: header injection
MEDIUM 5.9
CVE-2026-29772
Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands
MEDIUM 6.5
CVE-2026-27829
Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize
MEDIUM 5.9
CVE-2026-27729
Astro has memory exhaustion DoS due to missing request body size limit in Server Actions
MEDIUM 6.1
CVE-2025-55303
Astro allows unauthorized third-party images in _image endpoint
UNKNOWN
CVE-2025-55207
@astrojs/node's trailing slash handling causes open redirect issue
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes