Astro: Malformed port in the Host header can crash the Node adapter
Published Sep 30, 2026
8.2
HIGHCVSS 4.0
EPSS 0.63%
Description
Astro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter builds a request URL from the Host header, and a malformed port can make that URL invalid. The recovery path reuses the same malformed host and throws an uncaught TypeError: Invalid URL before routing begins. In the default standalone configuration, the request returns an HTTP 500 response and the server continues running, but when staticHeaders is enabled the synchronous handler does not catch the exception and the Node process terminates. Proxies and CDNs that reject malformed Host headers prevent this path from reaching the origin. The issue affects availability only and does not expose data or permit code execution. This issue is fixed in version 11.1.3.
Affected products
-
- Version < 11.1.3StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
@astrojs/node
npm
Introduced 0 Fixed 11.1.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @astrojs/node | 0 | 11.1.3 |
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 30, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (6)
- https://github.com/advisories/GHSA-qh8j-hqjv-7m4x Advisory
- https://github.com/withastro/astro/commit/2066f39c60707a100531b4ef4bb5dab8feafa7f2 x_refsource_MISC
- https://github.com/withastro/astro/pull/17572 x_refsource_MISC
- https://github.com/withastro/astro/releases/tag/@astrojs/node@11.1.3 x_refsource_MISC
- https://github.com/withastro/astro/security/advisories/GHSA-qh8j-hqjv-7m4x x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-102984
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-qh8j-hqjv-7m4x | Advisory | |
| https://github.com/withastro/astro/commit/2066f39c60707a100531b4ef4bb5dab8feafa7f2 | x_refsource_MISC | |
| https://github.com/withastro/astro/pull/17572 | x_refsource_MISC | |
| https://github.com/withastro/astro/releases/tag/@astrojs/node@11.1.3 | x_refsource_MISC | |
| https://github.com/withastro/astro/security/advisories/GHSA-qh8j-hqjv-7m4x | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-102984 |
Change history (0)
No recorded changes yet.