CVE-2026-102983
Description
Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL. Because Netlify evaluates these expressions with RegExp.test(), an allowed origin appearing only in a source URL's path or query can satisfy image.domains or image.remotePatterns while the URL's actual host remains attacker-controlled. An unauthenticated request to the public /.netlify/images endpoint can therefore cause the Image CDN to request attacker-selected URLs and may probe or reach internal services. Netlify egress protections may constrain reachable targets, and image transformation limits direct response exfiltration; no confidentiality or integrity impact has been demonstrated. This issue is fixed in version 8.2.4.
Is your site exposed to CVE-2026-102983?
Run a free security scan — no signup, results in seconds.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-102983? +
How do I check if I'm vulnerable to CVE-2026-102983? +
Related Vulnerabilities
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.11 until 0.9.12, …
Permissive Regular Expression vulnerability in ash-project ash_phoenix lets a remote client select the tenant an Ash application uses, or degrade …
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.10 until 0.9.12, …
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0 until 0.9.12, …
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome extension origins with re.match() and …
sanic-cors version 2.2.0 and prior contains an improper regular expression in the try_match() function in sanic_cors/core.py that uses re.match without …