Threat Advisory

Astro Vulnerabilities Let Malformed Request Fields Stop Workloads

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

 [/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

 [emaillocker id="1283"]

Astro is affected by two vulnerabilities impacting @astrojs/netlify and @astrojs/node. The @astrojs/netlify adapter allows unauthenticated SSRF through an improperly anchored Netlify Image CDN remote-image allowlist potentially enabling requests to attacker-selected or internal services. The @astrojs/node adapter allows a malformed Host header to trigger an uncaught exception potentially terminating the Node process when staticHeaders: true is enabled. Both issues have patches available.

CVE-2026-102984 (CVSS 8.2 — High): A malformed port in the Host header can crash the Node adapter, leading to an uncaught TypeError: Invalid URL while the request is being built. This vulnerability requires sending a hand-crafted Host header and can be exploited by an authenticated attacker.

CVE-2026-102983 (CVSS 6.3 — Medium): The @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL, allowing an unauthenticated attacker to bypass the configured image.domains or image.remotePatterns allowlist through the public /.netlify/images endpoint.

 

RECOMMENDATIONS:

 

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-qh8j-hqjv-7m4x
https://github.com/advisories/GHSA-4233-jc72-56c5

[/emaillocker]
crossmenu