CVE-2026-41321 | withastro up to 13.1.9 HTTP Redirect image-binding-transform.ts fetch server-side request forgery (GHSA-88gm-j2wx-58h6)
A vulnerability labeled as critical has been found in withastro astro up to 13.1.9. Affected by this vulnerability is the function fetch of the file packages/integrations/cloudflare/src/utils/image-binding-transform.ts of the component HTTP Redirect Handler. The manipulation results in server-side request forgery.
This vulnerability is reported as CVE-2026-41321. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.