CVE-2026-102984: Astro: Malformed port in the Host header can crash the Node adapter
Summary
In the Astro Node adapter, a request whose Host header contains a malformed port (for example example.com:65536 or example.com:8080:8080) produced an invalid request URL. The fallback intended to recover from an unparseable URL reused the same malformed host, so it failed again and raised an uncaught TypeError: Invalid URL while the request was being built, before any route ran.
Impact
The effect depends on the adapter configuration:
- Default configuration (standalone): the request returns 500 Internal Server Error and the server continues running. - With the opt-in staticHeaders: true option: the throw reaches a synchronous HTTP handler that does not catch it, becoming an uncaughtException that terminates the process.
This is an availability-only issue. It does not expose data or allow code execution. Triggering it requires sending a hand-crafted Host header, and many proxies and CDNs reject malformed hosts before they reach the origin.
Affected versions
@astrojs/node <= 11.1.2.
Patches
Fixed in @astrojs/node 11.1.3. When the incoming host cannot be parsed, the request URL now degrades to a host the server controls, so the request is handled instead of throwing. Hosts carrying more than a single hostname:port pair are also rejected during host validation.
Workarounds
Upgrade to @astrojs/node 11.1.3 or later. Deployments that terminate malformed Host headers at a reverse proxy or CDN are not reachable through this path.
Credits
Reported by @Celggar.
Other sources
Astro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter builds a request URL from the Host header, and a malformed port can make that URL invalid. The recovery path reuses the same malformed host and throws an uncaught TypeError: Invalid URL before routing begins. In the default standalone configuration, the request returns an HTTP 500 response and the server continues running, but when staticHeaders is enabled the synchronous handler does not catch the exception and the Node process terminates. Proxies and CDNs that reject malformed Host headers prevent this path from reaching the origin. The issue affects availability only and does not expose data or permit code execution. This issue is fixed in version 11.1.3.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@astrojs/nodeto a version that resolves this vulnerability.Fixed in 11.1.3 - Upgrade
Upgrade
@astrojs/nodeto a version that resolves this vulnerability.Fixed in 11.1.3 - Compensating control
Configure the reverse proxy or CDN to reject malformed Host headers, including hosts with malformed ports, before they reach the origin.
Event History
Frequently Asked Questions
Which deployments are at risk of a process crash?
Deployments using the @astrojs/node adapter with staticHeaders enabled can have the Node process terminate when they receive a Host header containing a malformed port. In the default standalone configuration, the same request returns HTTP 500 while the server continues running.
What must an attacker be able to do to trigger the issue?
An attacker needs to send a request with a malformed port in the Host header that reaches the Astro origin. A proxy or CDN that rejects malformed Host headers prevents the request from reaching the vulnerable code path.
What is the impact beyond availability?
The issue affects availability only. The provided information indicates it does not expose data or allow code execution.
What should be done if an immediate upgrade is not possible?
Ensure a proxy or CDN in front of the origin rejects malformed Host headers, and avoid enabling staticHeaders where feasible. Upgrade @astrojs/node to version 11.1.3 when possible.