LOW2.2npm
GHSA-88gm-j2wx-58h6· CVE-2026-41321Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4)
Modified: 5/5/2026
package
pkg:npm/%40astrojs/cloudflare
Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4)
Modified: 5/5/2026
Server-Side Request Forgery via /_image endpoint in Astro Cloudflare adapter
Modified: 9/5/2025