๐Ÿ” CVE Alert

CVE-2026-102984

UNKNOWN 0.0

Astro: Malformed port in the Host header can crash the Node adapter

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Astro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter builds a request URL from the Host header, and a malformed port can make that URL invalid. The recovery path reuses the same malformed host and throws an uncaught TypeError: Invalid URL before routing begins. In the default standalone configuration, the request returns an HTTP 500 response and the server continues running, but when staticHeaders is enabled the synchronous handler does not catch the exception and the Node process terminates. Proxies and CDNs that reject malformed Host headers prevent this path from reaching the origin. The issue affects availability only and does not expose data or permit code execution. This issue is fixed in version 11.1.3.

CWE CWE-248
Vendor withastro
Product astro
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for withastro astro

Be the first to know when new unknown vulnerabilities affecting withastro astro are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

withastro / astro
< 11.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/withastro/astro/security/advisories/GHSA-qh8j-hqjv-7m4x github.com: https://github.com/withastro/astro/pull/17572 github.com: https://github.com/withastro/astro/commit/2066f39c60707a100531b4ef4bb5dab8feafa7f2 github.com: https://github.com/withastro/astro/releases/tag/@astrojs/[email protected]