What is CVE-2026-73424?
CVE-2026-73424 is a critical vulnerability in the Astro web framework. From versions 10.0.3 to 11.0.3, the Vercel adapter's /_isr function accepts x_astro_path based solely on the x-vercel-isr header, allowing unauthenticated GET requests. Immediate patching is required to mitigate this issue.
Azərbaycanca: CVE-2026-73424 Astro veb framework-ində kritik boşluqdur. 10.0.3-dən 11.0.3-ə qədər versiyalarda Vercel adapterinin /_isr funksiyası x_astro_path parametrini yalnız x-vercel-isr header-ı əsasında qəbul edir ki, bu da autentifikasiyasız GET sorğularına imkan verir. Bu problemi aradan qaldırmaq üçün dərhal patching tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
What framework does CVE-2026-73424 affect?
CVE-2026-73424 is a critical vulnerability found in the Astro web framework.
How is CVE-2026-73424 exploited?
The Vercel adapter's /_isr function accepts the x_astro_path parameter based solely on the x-vercel-isr header, allowing unauthenticated GET requests.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.