{"id":"GHSA-4233-jc72-56c5","summary":"Astro: Netlify Image CDN allowlist bypass enables SSRF","details":"## Summary\n\nThe `@astrojs/netlify` adapter generated regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL. Netlify evaluates these expressions with `RegExp.test()`, so an allowed image origin appearing anywhere in a URL, including its path or query string, could satisfy the allowlist.\n\nFor example, an application allowing `images.example.com` could accept a source URL such as:\n\n```text\nhttp://127.0.0.1:6379/?url=https://images.example.com/image.png\n```\n\nThe allowlist matched the approved origin in the query string, but Netlify parsed and fetched the URL whose actual host was `127.0.0.1`.\n\n## Impact\n\nAn unauthenticated attacker can bypass the configured `image.domains` or `image.remotePatterns` allowlist through the public `/.netlify/images` endpoint and cause Netlify Image CDN to make requests to attacker-selected URLs. This may allow probing or reaching internal services, depending on Netlify's network-level egress protections.\n\nThe Image CDN attempts to transform responses as images, which limits direct response exfiltration. No confidentiality or integrity impact has been demonstrated.\n\n## Affected versions\n\n`@astrojs/netlify` versions from 5.2.0 through 8.2.3.\n\n## Patches\n\nFixed in `@astrojs/netlify` 8.2.4. Generated remote-image allowlist expressions are now anchored to both the beginning and end of the source URL.\n\n## Workarounds\n\nUpgrade to `@astrojs/netlify` 8.2.4 or later. Before upgrading, disable Netlify Image CDN by setting `imageCDN: false` in the adapter configuration, or remove remote image allowlist entries.\n\n## Credits\n\nReported by @pacocartones.","aliases":["CVE-2026-102983"],"modified":"2026-09-30T23:45:04.012782965Z","published":"2026-09-30T23:40:12Z","database_specific":{"github_reviewed_at":"2026-09-30T23:40:12Z","nvd_published_at":"2026-09-30T15:22:22Z","cwe_ids":["CWE-625","CWE-918"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/withastro/astro/security/advisories/GHSA-4233-jc72-56c5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102983"},{"type":"WEB","url":"https://github.com/withastro/astro/pull/17752"},{"type":"WEB","url":"https://github.com/withastro/astro/commit/e362d4cf540b27730482455c8fc02efe57d16702"},{"type":"PACKAGE","url":"https://github.com/withastro/astro"},{"type":"WEB","url":"https://github.com/withastro/astro/releases/tag/@astrojs/netlify@8.2.4"}],"affected":[{"package":{"name":"@astrojs/netlify","ecosystem":"npm","purl":"pkg:npm/%40astrojs/netlify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.2.0"},{"fixed":"8.2.4"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 8.2.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-4233-jc72-56c5/GHSA-4233-jc72-56c5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}