Vulnerabilities

3 via 5 paths

Dependencies

216

Source

GitHub

Find, fix and prevent vulnerabilities in your code.

Issue type
  • 3
  • 1
Severity
  • 3
  • 1
Status
  • 4
  • 0
  • 0

high severity
new

Improper Authorization

  • Vulnerable module: http-cache-semantics
  • Introduced through: astro@7.3.5

Detailed paths

  • Introduced through: @arthelokyo/astrowind@arthelokyo/astrowind › astro@7.3.5 › http-cache-semantics@4.3.0

Overview

Affected versions of this package are vulnerable to Improper Authorization via improper validation of security-zeroed cache entries when processing client max-stale directives. An unauthenticated attacker can request the same URL with a large max-stale value to retrieve cached responses belonging to other users, including Set-Cookie session credentials from shared-cache entries that were deliberately zeroed for security reasons.

Remediation

There is no fixed version for http-cache-semantics.

References

high severity
new

Allocation of Resources Without Limits or Throttling

  • Vulnerable module: zod
  • Introduced through: @astrojs/rss@4.0.19, @astrojs/sitemap@3.7.4 and others

Detailed paths

  • Introduced through: @arthelokyo/astrowind@arthelokyo/astrowind › @astrojs/rss@4.0.19 › zod@4.6.5
  • Introduced through: @arthelokyo/astrowind@arthelokyo/astrowind › @astrojs/sitemap@3.7.4 › zod@4.6.5
  • Introduced through: @arthelokyo/astrowind@arthelokyo/astrowind › astro@7.3.5 › zod@4.6.5

Overview

zod is a TypeScript-first schema declaration and validation library with static type inference

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the handleArrayResult parse logic in $ZodArray, which accumulates every validation issue for each failing element in a large array with no cap or early termination. An attacker can submit a large array to an application using an array schema without a length constraint, causing the process to allocate excessive issue objects and crash due to out-of-memory conditions.

Remediation

There is no fixed version for zod.

References

high severity
new

Origin Validation Error

  • Vulnerable module: http-cache-semantics
  • Introduced through: astro@7.3.5

Detailed paths

  • Introduced through: @arthelokyo/astrowind@arthelokyo/astrowind › astro@7.3.5 › http-cache-semantics@4.3.0

Overview

Affected versions of this package are vulnerable to Origin Validation Error via the _varyMatches() function, which fails to properly handle Vary: * (wildcard) headers due to byte-for-byte string comparison. An attacker can request URLs previously fetched by other clients to receive cached responses intended for different users, disclosing sensitive information across clients. The Vary: * directive signals that a response is uncacheable for any other request, but the flawed comparison allows the wildcard to be bypassed, enabling cross-client cache disclosure.

Remediation

There is no fixed version for http-cache-semantics.

References

medium severity

MPL-2.0 license

  • Module: lightningcss
  • Introduced through: astro@7.3.5

Detailed paths

  • Introduced through: @arthelokyo/astrowind@arthelokyo/astrowind › astro@7.3.5 › vite@8.3.2 › lightningcss@1.33.0

MPL-2.0 license