Denial of Service in Astro Web Framework Affecting @astrojs/node Adapter
CVE-2026-102984
8.2HIGH
What is CVE-2026-102984?
The Astro web framework, specifically the @astrojs/node adapter prior to version 11.1.3, suffers from a vulnerability where a malformed Host header can lead to an uncaught TypeError. In standalone configurations, this results in an HTTP 500 response, impacting service availability. Although the malformed request may not lead to data exposure or code execution, users may experience disrupted services. Proxies and CDNs that reject such malformed headers potentially mitigate the issue, but the vulnerability remains significant in default setups. Updating to version 11.1.3 addresses this problem by implementing proper error handling.
Affected Version(s)
astro < 11.1.3
