Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.3 Node.js & npm GHSA-qh8j-hqjv-7m4x CVE-2026-102984 GHSA-4233-jc72-56c5 CVE-2026-102983

Two Astro Adapter Vulnerabilities: Node DoS via Malformed Host Header and Netlify Image CDN SSRF Risk

Astro's @astrojs/node adapter can crash under a malformed Host header when staticHeaders is enabled (CVE-2026-102984), while @astrojs/netlify's Image CDN allowlist can be bypassed to trigger server-side requests to attacker-chosen URLs (CVE-2026-102983). Fixes are available for both.

AI summary

Two separate vulnerabilities affecting Astro framework adapters have been disclosed. The first impacts the @astrojs/node adapter, where a malformed Host header can cause an uncaught exception that, under certain configurations, terminates the Node process. The second affects the @astrojs/netlify adapter, where an unanchored regular expression used to validate Image CDN remote-image allowlists can be bypassed, potentially allowing requests to attacker-controlled URLs. Both issues have been fixed by the Astro project and have no evidence of active exploitation.

What Happened

Two advisories were published for Astro adapters. In @astrojs/node, the adapter builds a request URL from the incoming Host header; if the header contains a malformed port, this can produce an invalid URL. The adapter's recovery path reuses the same malformed host and throws an uncaught TypeError before routing occurs. In the default standalone configuration this results in an HTTP 500 response and the server keeps running, but when the staticHeaders option is enabled, the exception is not caught by the synchronous handler and the Node process terminates. Separately, in @astrojs/netlify, the adapter generates regular expressions to validate remote-image allowlists (image.domains / image.remotePatterns) for the Netlify Image CDN, but these expressions are not anchored to the start of the URL. Because Netlify evaluates them with RegExp.test(), an allowed origin appearing anywhere in a URL's path or query string can satisfy the check even though the actual host is different and attacker-controlled. This can let an unauthenticated request to the public /.netlify/images endpoint cause the Image CDN to fetch attacker-selected URLs.

Technical Cause

CVE-2026-102984 (CWE-248, Uncaught Exception) stems from insufficient validation of the Host header before constructing a URL object; a malformed port value triggers an invalid-URL error that is not handled gracefully in the staticHeaders code path. CVE-2026-102983 (CWE-625, Permissive Regular Expression) stems from allowlist regular expressions that are not anchored to the beginning of the input string, allowing a string match on an allowed domain to succeed even when it does not represent the actual host of the target URL.

Why It Matters

The Node adapter issue affects availability only: it does not expose data or permit code execution, but in the staticHeaders configuration a single malformed request can crash the server process, requiring a restart. The advisory notes that proxies and CDNs that reject malformed Host headers before they reach the origin can prevent this path from being reached. The Netlify adapter issue is a Server-Side Request Forgery (SSRF) enabler: it could let an unauthenticated requester cause the Image CDN to make requests to internal or otherwise unintended targets. The advisory states that Netlify's own egress protections may constrain which targets are reachable, and that image transformation limits make direct response exfiltration difficult; no confidentiality or integrity impact has been demonstrated to date.

Who Is Affected

Sites using the @astrojs/node adapter with the staticHeaders option enabled are affected by CVE-2026-102984; sites in the default standalone configuration experience a less severe HTTP 500 response rather than a crash. Sites using the @astrojs/netlify adapter with image.domains or image.remotePatterns configured for the Netlify Image CDN are affected by CVE-2026-102983. Both vulnerabilities can be triggered by unauthenticated requests and require no user interaction.

Affected Versions

@astrojs/node: versions from 0 up to and including 11.1.2 are affected (CVE-2026-102984). @astrojs/netlify: versions from 5.2.0 up to and including 8.2.3 are affected (CVE-2026-102983).

Fixes and Mitigation

@astrojs/node version 11.1.3 fixes CVE-2026-102984. @astrojs/netlify version 8.2.4 fixes CVE-2026-102983. As a partial mitigation for the Node adapter issue, deploying a proxy or CDN in front of the origin that rejects malformed Host headers can prevent the vulnerable path from being reached, though this is not a substitute for upgrading.

Recommended Action

Upgrade @astrojs/node to version 11.1.3 or later, particularly if staticHeaders is enabled. Upgrade @astrojs/netlify to version 8.2.4 or later if remote-image allowlisting is configured for the Netlify Image CDN. Review deployment configurations to confirm which adapters and options are in use before prioritizing remediation.

PatchBriefing score

5.3 / 10 · Medium

Official CVSS: 8.2

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Why this score

CVE-2026-102984 has a CVSS score of 8.2, reflecting a network-exploitable, unauthenticated, no-user-interaction issue with a high availability impact in the affected configuration; this maps to a PatchBriefing score of 5.3, with no known exploitation or public exploit code reducing urgency beyond the base severity. CVE-2026-102983 has a CVSS score of 6.3, reflecting a network-exploitable, unauthenticated SSRF-enabling flaw with a low availability impact and undemonstrated confidentiality/integrity impact; this maps to a PatchBriefing score of 4.3. Neither vulnerability is known to be exploited in the wild and no public exploit code has been reported for either.

Affected versions

@astrojs/node <= 11.1.2
vulnerable
≥ 11.1.3
patched
@astrojs/netlify >= 5.2.0, <= 8.2.3
vulnerable
≥ 8.2.4
patched

Reported fixes

@astrojs/node version 11.1.3 fixes CVE-2026-102984. @astrojs/netlify version 8.2.4 fixes CVE-2026-102983. As a partial mitigation for the Node adapter issue, deploying a proxy or CDN in front of the origin that rejects malformed Host headers can prevent the vulnerable path from being reached, though this is not a substitute for upgrading.

How this was built

4 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
Two Astro Adapter Vulnerabilities: Node DoS via Malformed Host Header and Netlify Image CDN SSRF Risk
1 article · 4 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email