Denial of Service in Astro Web Framework Affecting @astrojs/node Adapter
CVE-2026-102984

8.2HIGH

Key Information:

Vendor

Withastro

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102984?

The Astro web framework, specifically the @astrojs/node adapter prior to version 11.1.3, suffers from a vulnerability where a malformed Host header can lead to an uncaught TypeError. In standalone configurations, this results in an HTTP 500 response, impacting service availability. Although the malformed request may not lead to data exposure or code execution, users may experience disrupted services. Proxies and CDNs that reject such malformed headers potentially mitigate the issue, but the vulnerability remains significant in default setups. Updating to version 11.1.3 addresses this problem by implementing proper error handling.

Affected Version(s)

astro < 11.1.3

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.