---
id: CVE-2026-102984
title: Astro is a web framework for content-driven websites
summary: >-
  Astro is a web framework for content-driven websites. Prior to 11.1.3, the
  @astrojs/node adapter builds a request URL from the Host header, and a
  malformed port can make that URL invalid. The recovery path reuses the same
  malformed host …
severity: high
cvss: 8.2
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-248
vendor: withastro
product: astro
affected:
  - astro < 11.1.3
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T15:22:23.490'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102984'
references:
  - url: >-
      https://github.com/withastro/astro/commit/2066f39c60707a100531b4ef4bb5dab8feafa7f2
    label: security-advisories@github.com
  - url: 'https://github.com/withastro/astro/pull/17572'
    label: security-advisories@github.com
  - url: 'https://github.com/withastro/astro/releases/tag/@astrojs/node@11.1.3'
    label: security-advisories@github.com
  - url: 'https://github.com/withastro/astro/security/advisories/GHSA-qh8j-hqjv-7m4x'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-30T15:07:05.383Z'
---

## Overview

Astro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter builds a request URL from the Host header, and a malformed port can make that URL invalid. The recovery path reuses the same malformed host and throws an uncaught TypeError: Invalid URL before routing begins. In the default standalone configuration, the request returns an HTTP 500 response and the server continues running, but when staticHeaders is enabled the synchronous handler does not catch the exception and the Node process terminates. Proxies and CDNs that reject malformed Host headers prevent this path from reaching the origin. The issue affects availability only and does not expose data or permit code execution. This issue is fixed in version 11.1.3.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
