EXECUTIVE SUMMARY
[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
[emaillocker id="1283"]
Astro is affected by two vulnerabilities impacting @astrojs/netlify and @astrojs/node. The @astrojs/netlify adapter allows unauthenticated SSRF through an improperly anchored Netlify Image CDN remote-image allowlist potentially enabling requests to attacker-selected or internal services. The @astrojs/node adapter allows a malformed Host header to trigger an uncaught exception potentially terminating the Node process when staticHeaders: true is enabled. Both issues have patches available.
CVE-2026-102984 (CVSS 8.2 — High): A malformed port in the Host header can crash the Node adapter, leading to an uncaught TypeError: Invalid URL while the request is being built. This vulnerability requires sending a hand-crafted Host header and can be exploited by an authenticated attacker.
CVE-2026-102983 (CVSS 6.3 — Medium): The @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL, allowing an unauthenticated attacker to bypass the configured image.domains or image.remotePatterns allowlist through the public /.netlify/images endpoint.
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-qh8j-hqjv-7m4x
https://github.com/advisories/GHSA-4233-jc72-56c5