CVE-2026-102983
Received Received - Intake

RegExp Bypass in Astro Netlify Adapter Image CDN

Vulnerability report for CVE-2026-102983, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL. Because Netlify evaluates these expressions with RegExp.test(), an allowed origin appearing only in a source URL's path or query can satisfy image.domains or image.remotePatterns while the URL's actual host remains attacker-controlled. An unauthenticated request to the public /.netlify/images endpoint can therefore cause the Image CDN to request attacker-selected URLs and may probe or reach internal services. Netlify egress protections may constrain reachable targets, and image transformation limits direct response exfiltration; no confidentiality or integrity impact has been demonstrated. This issue is fixed in version 8.2.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
astro astro *
astrojs netlify From 5.2.0 (inc) to 8.2.4 (exc)
astrojs netlify 8.2.4
astrojs astro From 5.2.0 (inc) to 8.2.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-625 The product uses a regular expression that does not sufficiently restrict the set of allowed values.
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Astro framework's Netlify integration. It allows unauthenticated attackers to bypass image domain allowlists by embedding allowed domains in URL paths or query strings. The issue occurs because the adapter generates unanchored regular expressions for remote-image allowlists, which Netlify evaluates incorrectly. This could let attackers probe or access internal services via the public /.netlify/images endpoint.

Detection Guidance

To detect this vulnerability, check if your Astro project uses the @astrojs/netlify adapter versions between 5.2.0 and 8.2.3. Inspect your project's package.json for the adapter version. If vulnerable, the Netlify Image CDN may allow unauthorized URL fetching through the /.netlify/images endpoint.

Impact Analysis

An attacker could craft malicious URLs that bypass image domain restrictions, potentially accessing internal services or probing networks. While direct data exfiltration is limited by Image CDN transformations, the vulnerability enables unauthorized requests to restricted resources. Impact depends on Netlify's egress protections and network configuration.

Mitigation Strategies

Upgrade the @astrojs/netlify adapter to version 8.2.4 or later. Alternatively, disable the Netlify Image CDN by setting imageCDN: false in your adapter configuration or remove remote image allowlist entries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102983. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart