Skip to content

@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped

Low
matthewp published GHSA-hp3v-mfqw-h74c Jul 15, 2026

Package

npm @astrojs/netlify (npm)

Affected versions

<= 8.1.1

Patched versions

8.1.2

Description

Summary

The @astrojs/netlify adapter converts each image.remotePatterns entry into a regular expression that is written to .netlify/v1/config.json under images.remote_images. Netlify's Image CDN uses these regexes as the allowlist that decides which remote image URLs it will optimize. remotePatternToRegex() escapes . in the hostname but interpolates the literal pathname into the regex without escaping regex metacharacters. As a result, the generated allowlist is broader than the pattern the developer declared, and broader than Astro's canonical matchPattern() helper (which compares non-wildcard pathnames by exact string equality).

This is a residual of the same bug class addressed in CVE-2026-54300 (PR #17018, commit 1310277d). That fix corrected wildcard semantics and added a $ anchor but did not add metacharacter escaping for literal pathnames.

Details

In packages/integrations/netlify/src/index.ts, remotePatternToRegex() escapes dots in the hostname:

regexStr += hostname.replace(/\./g, '\\.');

but interpolates the pathname unescaped in all three branches, e.g. the exact-match branch:

regexStr += `(\\${pathname})`;

Any regex metacharacter in the literal path (., +, ?, (, [, ...) is therefore passed through raw. Because . matches any character (including /), a restrictive pattern is silently widened.

The security boundary on Netlify is the generated regex itself — Netlify's Image CDN enforces it directly and Astro's runtime matchPattern() is not in the loop for this path, so there is no compensating layer that re-validates the request.

Proof of Concept

Configure an SSR site with a literal pathname containing a .:

// astro.config.mjs
image: {
  remotePatterns: [{
    protocol: 'https',
    hostname: 'cdn.example.com',
    pathname: '/img/v1.0/file',
  }],
}

Run astro build and inspect .netlify/v1/config.json images.remote_images[0]:

https://cdn\.example\.com(:[0-9]+)?(\/img/v1.0/file)([?][^#]*)?$

Testing the generated regex:

  • https://cdn.example.com/img/v1.0/file -> MATCH (intended)
  • https://cdn.example.com/img/v1X0/file -> MATCH (bypass; the unescaped . matches any character)
  • https://cdn.example.com/img/v1/0/file -> MATCH (bypass; . also matches /, crossing a path segment)

Astro's canonical matchPattern() (exact string equality on the pathname) rejects both bypass URLs.

Impact

Netlify's Image CDN accepts optimization requests for URLs on the allowed host that the developer's remotePatterns entry was intended to exclude. The hostname remains correctly anchored, so the broadening is confined to the pathname dimension on an already-allowed host. Realistic impact depends on whether other images the developer meant to keep out of their CDN exist at metacharacter-adjacent paths on that host. This affects reasonable, non-permissive configurations, since any pathname containing a . (file extensions, version segments) is affected.

Patches

A fix will escape all regex metacharacters in the literal portions of each remotePatterns component before interpolation, applying only Astro's documented wildcard semantics explicitly. A regression corpus validates the generated Netlify regexes against @astrojs/internal-helpers' matchPattern().

Workarounds

Avoid regex metacharacters (notably .) in image.remotePatterns[].pathname values, or scope the allowed host so that unintended paths are not reachable.

References

  • Prior related advisory: CVE-2026-54300
  • Fix that introduced the residual: PR #17018 (commit 1310277d)

Credit

Reported by @sec-reex as part of an incomplete-patch measurement study (responsible disclosure).

Severity

Low

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CVE ID

CVE-2026-73425

Weaknesses

No CWEs

Credits