GHSA-qpr4-c339-7vq8
HIGHCVE-2025-58179When using Astro's Cloudflare adapter (@astrojs/cloudflare) configured with output: 'server' while using the default imageService: 'compile', the generated image optimization endpoint doesn't check the URLs it receives, allowing content from unauthorized third-party domains to be served.
- Affected
- >= 11.0.3, < 12.6.6
- Fixed in
- 12.6.6
- Weakness
- CWE-918
- Published
- 2025-09-04
- Source
- github