Reusing a Nonce, Key Pair in Encryption Affecting astro package, versions <6.1.10


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.02% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-ASTRO-16643260
  • published13 May 2026
  • disclosed13 May 2026
  • creditPopax21

Introduced: 13 May 2026

NewCVE-2026-45028  (opens in a new tab)
CWE-323  (opens in a new tab)

How to fix?

Upgrade astro to version 6.1.10 or higher.

Overview

astro is an Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Affected versions of this package are vulnerable to Reusing a Nonce, Key Pair in Encryption of server island parameters. An attacker can inject malicious HTML or script content into a component by replaying encrypted values between props and slots across different components.

Note: This is only exploitable if the application uses server islands, two different server island components share the same key name for a prop and a slot, and an attacker has full control over the value of the overlapping prop in a dynamically rendered page.

CVSS Base Scores

version 4.0
version 3.1