Heap-based Buffer Overflow Affecting astro package, versions <7.2.8


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-ASTRO-19652369
  • published9 Sept 2026
  • disclosed8 Sept 2026
  • creditcn-panda

Introduced: 8 Sep 2026

New CVE NOT AVAILABLE CWE-122  (opens in a new tab)

How to fix?

Upgrade astro to version 7.2.8 or higher.

Overview

astro is an Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Affected versions of this package are vulnerable to Heap-based Buffer Overflow due to the Sharp image optimization. An attacker can execute code on the server by supplying a malicious AVIF image for Astro to process through its default Sharp-based image service. When Astro optimizes untrusted AVIF content, the underlying libheif dependency used by Sharp can be triggered during image handling, allowing the attacker to compromise the application process that performs the optimization. This can crash or fully take over the server-side image processing workflow, putting the deployment at risk.

CVSS Base Scores

version 4.0
version 3.1