Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path enforcement for remote URLs used by server-side fetchers such as the image optimization endpoint. The path matching logic for /* wildcards is unanchored, so a pathname that contains the allowed prefix later in the path can still match. As a result, an attacker can fetch paths outside the intended allowlisted prefix on an otherwise allowed host. This issue has been patched in version 5.18.1.
We have discovered 17,726 live websites that are affected by CVE-2026-33769.
| Product | |
| Category | Static Site Generator |
| Vulnerable Domains | 17,726 live websites (91% of Astro install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 312 versions ( 72% of all versions) |
| 10,843 websites | |
| 1,149 websites | |
| 523 websites | |
| 475 websites | |
| 387 websites | |
| 249 websites | |
| 245 websites | |
| 242 websites | |
| 235 websites | |
| 202 websites |
| .com | 8,447 websites |
| .de | 687 websites |
| .org | 637 websites |
| .net | 611 websites |
| .co.uk | 367 websites |
| .fr | 302 websites |
| .io | 298 websites |
| .nl | 233 websites |
| .pl | 206 websites |
| .com.au | 193 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **.cn | *** | ||
| ************.com | *,*** | ||
| **********.com | *,*** | ||
| ********.jp | *,*** | ||
| *****.com | *,*** | ||
| ***********.com | *,*** | ||
| *******.io | *,*** | ||
| ******.com | *,*** | ||
| ****.com | *,*** | ||
| ***********.se | *,*** |
FAQ