Server-side Request Forgery (SSRF) Affecting @astrojs/netlify package, versions >=5.2.0 <8.2.4


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.31% (22nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-ASTROJSNETLIFY-20419250
  • published4 Oct 2026
  • disclosed30 Sept 2026
  • creditPaco Cartones

Introduced: 30 Sep 2026

NewCVE-2026-102983  (opens in a new tab)
CWE-625  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade @astrojs/netlify to version 8.2.4 or higher.

Overview

@astrojs/netlify is a Deploy your site to Netlify

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) through a permissive regular expression in remotePatternToRegex() and the image.domains mapping in remoteImagesFromAstroConfig() in packages/integrations/netlify/src/index.ts, which build the Netlify Image CDN allowlist entries without anchoring them, so an allowed origin satisfies the pattern wherever it appears in a candidate URL rather than only at the start. An attacker can direct the Image CDN to fetch an address of their choosing, including internal services and cloud metadata endpoints, by placing an allowed origin in the path or query string of the target URL, as in http://127.0.0.1:6379/?url=https://images.example.com/image.png. This requires the application to have configured image.domains or image.remotePatterns, since the allowlist is what is being matched against, and requests reach the fetch through the public /.netlify/images endpoint.

Workaround

This vulnerability can be avoided by disabling the Image CDN in the adapter configuration.

CVSS Base Scores

version 4.0
version 3.1