Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize
A bug in Astro's image pipeline allows bypassing image.domains / image.remotePatterns restrictions, enabling the server to fetch content from unauthorized remote hosts.