GHSA-qh8j-hqjv-7m4x: Npm/@astrojs/node vulnerability

Published Sep 30, 2026
·
Updated

Summary

In the Astro Node adapter, a request whose Host header contains a malformed port (for example example.com:65536 or example.com:8080:8080) produced an invalid request URL. The fallback intended to recover from an unparseable URL reused the same malformed host, so it failed again and raised an uncaught TypeError: Invalid URL while the request was being built, before any route ran.

Impact

The effect depends on the adapter configuration:

- Default configuration (standalone): the request returns 500 Internal Server Error and the server continues running. - With the opt-in staticHeaders: true option: the throw reaches a synchronous HTTP handler that does not catch it, becoming an uncaughtException that terminates the process.

This is an availability-only issue. It does not expose data or allow code execution. Triggering it requires sending a hand-crafted Host header, and many proxies and CDNs reject malformed hosts before they reach the origin.

Affected versions

@astrojs/node <= 11.1.2.

Patches

Fixed in @astrojs/node 11.1.3. When the incoming host cannot be parsed, the request URL now degrades to a host the server controls, so the request is handled instead of throwing. Hosts carrying more than a single hostname:port pair are also rejected during host validation.

Workarounds

Upgrade to @astrojs/node 11.1.3 or later. Deployments that terminate malformed Host headers at a reverse proxy or CDN are not reachable through this path.

Credits

Reported by @Celggar.

Affected Software

1 affected componentFixes available
npm/@astrojs/node<=11.1.2
11.1.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@astrojs/node to a version that resolves this vulnerability.

    Fixed in 11.1.3
  2. Upgrade

    Upgrade @astrojs/node to a version that resolves this vulnerability.

    Fixed in 11.1.3

Event History

Sep 30, 2026
Advisory Published
via GitHub·11:29 PM
Data Sourced
via GitHub·11:29 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

When can this lead to a process crash rather than a failed request?

A process crash occurs only when the Astro Node adapter is configured with the opt-in staticHeaders: true option. In the default standalone configuration, the malformed request instead receives a 500 Internal Server Error and the server continues running.

2

What must an attacker be able to do to trigger the issue?

They must send a request with a deliberately malformed Host header, such as one containing an invalid or repeated port. Proxies and CDNs may prevent exploitation if they reject malformed Host headers before forwarding requests to the origin.

3

How can I determine whether an installation is affected?

Installations using @astrojs/node version 11.1.2 or earlier are affected. Deployments using staticHeaders: true have the higher availability impact because a triggering request can terminate the process.

4

What is the remediation if the adapter is in use?

Upgrade @astrojs/node to version 11.1.3, which handles an unparseable incoming host by using a server-controlled host for the request URL. If upgrading cannot happen immediately, avoid enabling staticHeaders: true and ensure upstream infrastructure rejects malformed Host headers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203