Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102984— Astro: Malformed port in the Host header can crash the Node adapter

Quick assessment

Affected
withastro astro
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Astro 是一个面向内容驱动型网站的 Web 框架。在 11.1.3 版本之前,@astrojs/node 适配器会根据 Host 请求头构建请求 URL,而格式错误的端口可能导致该 URL 无效。在恢复处理路径中,系统会复用同一个格式错误的 Host 值,并在路由开始之前抛出未捕获的 TypeError: Invalid URL 异常。在默认的 standalone(独立)配置下,请求会返回 HTTP 500 响应,服务器继续运行;但当启用 staticHeaders 时,同步处理函数未能捕获该异常,导致 No

CVSS 8.2 · High EPSS 0.36% · P28

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 1

VendorProduct Version RangeStatus
withastro astro < 11.1.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-102984

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Astro: Malformed port in the Host header can crash the Node adapter
Source: CVE Program / CVE List V5
Vulnerability Description
Astro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter builds a request URL from the Host header, and a malformed port can make that URL invalid. The recovery path reuses the same malformed host and throws an uncaught TypeError: Invalid URL before routing begins. In the default standalone configuration, the request returns an HTTP 500 response and the server continues running, but when staticHeaders is enabled the synchronous handler does not catch the exception and the Node process terminates. Proxies and CDNs that reject malformed Host headers prevent this path from reaching the origin. The issue affects availability only and does not expose data or permit code execution. This issue is fixed in version 11.1.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
未捕获的异常
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
withastro astro < 11.1.3 -

II. Public POCs for CVE-2026-102984

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102984

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-102984 (2)

Vendor Advisories for CVE-2026-102984 (1)

Vendor Pages for CVE-2026-102984 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-102984

No comments yet


Leave a comment