CVE-2026-102983 Astro @astrojs/netlify 适配器 SSRF 漏洞
影响未认证攻击者可诱导 Image CDN 请求任意 URL,可能探测或访问内部服务
Astro 是面向内容驱动网站的 Web 框架,其 @astrojs/netlify 适配器用于生成 Netlify Image CDN 远程图片白名单正则。从 5.2.0 到 8.2.4 之前,该适配器生成的正则未锚定到 URL 开头,导致白名单校验可被绕过。攻击者可通过公开的 /.netlify/images 端点触发服务端请求伪造(SSRF)。
影响范围
漏洞详情
漏洞类型为服务端请求伪造(SSRF),成因是 @astrojs/netlify 适配器在生成 image.domains 或 image.remotePatterns 对应的正则时未使用起始锚点。Netlify 使用 RegExp.test() 进行匹配,因此只要允许的来源出现在源 URL 的路径或查询字符串中即可通过校验,而实际主机仍由攻击者控制。未认证请求 /.netlify/images 端点即可让 Image CDN 请求攻击者指定的 URL。
利用条件与风险
利用无需认证,仅需访问公开的 /.netlify/images 端点。Netlify 的出站防护可能限制可达目标,图片转换也限制了直接响应外泄,目前未证实机密性或完整性影响,但存在探测或触达内部服务的风险。
修复建议
升级 @astrojs/netlify 适配器至 8.2.4 或更高版本以修复正则锚定问题。临时缓解措施暂无公开信息,可考虑限制 /.netlify/images 端点的访问或收紧远程图片白名单配置。
Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL. Because Netlify evaluates these expressions with RegExp.test(), an allowed origin appearing only in a source URL’s path or query can satisfy image.domains or image.remotePatterns while the URL’s actual host remains attacker-controlled. An unauthenticated request to the public /.netlify/images endpoint can therefore cause the Image CDN to request attacker-selected URLs and may probe or reach internal services. Netlify egress protections may constrain reachable targets, and image transformation limits direct response exfiltration; no confidentiality or integrity impact has been demonstrated. This issue is fixed in version 8.2.4.