CVE-2026-33769

Astro: Remote allowlist bypass via unanchored matchPathname wildcard

Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path enforcement for remote URLs used by server-side fetchers such as the image optimization endpoint. The path matching logic for /* wildcards is unanchored, so a pathname that contains the allowed prefix later in the path can still match. As a result, an attacker can fetch paths outside the intended allowlisted prefix on an otherwise allowed host. This issue has been patched in version 5.18.1.


We have discovered 17,726 live websites that are affected by CVE-2026-33769.

Run a Free Instant Scan




Affected Software

Product  Astro
Category Static Site Generator
Vulnerable Domains17,726 live websites (91% of Astro install base)
Vulnerable Versions
  • from 2.10.10 through 5.18.1
Vulnerable Versions Count312 versions ( 72% of all versions)


Common Weakness Enumeration

CWE-20 Improper Input Validation



Details

  • Published - Mar 24, 2026
  • Updated - Mar 24, 2026

Website Distribution by Country

Number of websites using CVE-2026-33769
United States10,843 websites



Germany1,149 websites
GB523 websites
France475 websites
Japan387 websites
Spain249 websites
Canada245 websites
Poland242 websites
Netherlands235 websites
Australia202 websites

Website Distribution by TLD

Number of websites using CVE-2026-33769
.com8,447 websites
.de687 websites
.org637 websites
.net611 websites
.co.uk367 websites
.fr302 websites
.io298 websites
.nl233 websites
.pl206 websites
.com.au193 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-33769

Top websites that are affected by CVE-2026-33769. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**.cn China***
************.com United States*,***
**********.com United States*,***
********.jp Japan*,***
*****.com United States*,***
***********.com United States*,***
*******.io United States*,***
******.com India*,***
****.com United States*,***
***********.se United States*,***
See full domain list

FAQ

CVE-2026-33769 is Improper Input Validation in Astro
A total of 17,726 websites have been identified as vulnerable to CVE-2026-33769, based on global website indexing conducted by WebTechSurvey.
The Astro is affected by the CVE-2026-33769 vulnerability.
Astro versions up to 5.18.1 are vulnerable to CVE-2026-33769.
CVE-2026-33769 is resolved in version 5.18.1 of Astro.