CVE-2026-102984High· 8.2▾ TwilightAstro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter builds a request URL from the Host header, and a malformed port can make that URL invalid. The recovery path reuses the same malformed host …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Astro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter builds a request URL from the Host header, and a malformed port can make that URL invalid. The recovery path reuses the same malformed host and throws an uncaught TypeError: Invalid URL before routing begins. In the default standalone configuration, the request returns an HTTP 500 response and the server continues running, but when staticHeaders is enabled the synchronous handler does not catch the exception and the Node process terminates. Proxies and CDNs that reject malformed Host headers prevent this path from reaching the origin. The issue affects availability only and does not expose data or permit code execution. This issue is fixed in version 11.1.3.
astro < 11.1.3Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102983Medium· 6.3Astro: Netlify Image CDN allowlist bypass enables SSRF
GHSA-26w7-cxv4-gfx2Critical· 9.8Astro: Remote code execution through AVIF image optimization
CVE-2026-84376MediumAstro is a web framework for content-driven websites
CVE-2026-59727LowAstro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
CVE-2026-59729MediumAstro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
GHSA-8mv7-9c27-98vcMediumAstro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered