Vulnerabilities/

Server-Side Request Forgery via /_image endpoint in Astro Cloudflare adapter

Severity:
High

Description

When using Astro’s Cloudflare adapter (@astrojs/cloudflare) configured with output: 'server' while using the default imageService: 'compile', the generated image optimization endpoint doesn’t check the URLs it receives, allowing content from unauthorized third-party domains to be served.

Recommendation

Update the @astrojs/cloudflare package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@astrojs/cloudflare
Anything's wrong? Let us know Last updated on September 05, 2025

This issue is available in SmartScanner Professional

See Pricing