OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102984

HIGH · CVSS 8.2 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability affects the @astrojs/node adapter in the Astro web framework, where malformed Host headers can lead to an uncaught TypeError, resulting in a server crash under specific configurations. While the issue primarily impacts availability by causing HTTP 500 responses or terminating the Node process, it does not compromise data integrity or allow for code execution. Organizations using affected versions of Astro, particularly those with staticHeaders enabled, should prioritize upgrading to version 11.1.3 to mitigate potential downtime.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102984
Severity
HIGH
CVSS
8.2
EPSS
0.36%

Original NVD Description

Astro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter builds a request URL from the Host header, and a malformed port can make that URL invalid. The recovery path reuses the same malformed host and throws an uncaught TypeError: Invalid URL before routing begins. In the default standalone configuration, the request returns an HTTP 500 response and the server continues running, but when staticHeaders is enabled the synchronous handler does not catch the exception and the Node process terminates. Proxies and CDNs that reject malformed Host headers prevent this path from reaching the origin. The issue affects availability only and does not expose data or permit code execution. This issue is fixed in version 11.1.3.