{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aastroastrojs_node/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:astro:astrojs_node:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-102984"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@astrojs/node (\u003c= 11.1.2)"],"_cs_severities":["high"],"_cs_tags":["denial-of-service","webserver","vulnerability"],"_cs_type":"threat","_cs_vendors":["Astro"],"content_html":"\u003cp\u003eA vulnerability (CVE-2026-102984) exists in the \u003ccode\u003e@astrojs/node\u003c/code\u003e adapter (versions 11.1.2 and earlier) where improper validation of the \u003ccode\u003eHost\u003c/code\u003e header can lead to a denial-of-service condition. An attacker can craft a request with an invalid port specification within the \u003ccode\u003eHost\u003c/code\u003e header, such as \u003ccode\u003eexample.com:65536\u003c/code\u003e or \u003ccode\u003eexample.com:8080:8080\u003c/code\u003e. When the adapter attempts to process these requests, the logic fails to correctly generate a request URL and enters a recursive failure state. This results in an uncaught \u003ccode\u003eTypeError: Invalid URL\u003c/code\u003e exception. If the server is configured with \u003ccode\u003estaticHeaders: true\u003c/code\u003e, this exception remains unhandled, causing the entire Node.js process to terminate. This vulnerability is limited to availability disruption and does not facilitate data exfiltration or remote code execution.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability impacts applications using the \u003ccode\u003e@astrojs/node\u003c/code\u003e adapter, specifically those configured with the \u003ccode\u003estaticHeaders: true\u003c/code\u003e option, as these are susceptible to process termination. Successfully sending a crafted request to such an endpoint will crash the server, causing service downtime. Applications using the default \u003ccode\u003estandalone\u003c/code\u003e configuration will experience a \u003ccode\u003e500 Internal Server Error\u003c/code\u003e but will remain running. The attack surface is dependent on whether upstream infrastructure, such as CDNs or reverse proxies, filters malformed \u003ccode\u003eHost\u003c/code\u003e headers before they reach the Astro origin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to \u003ccode\u003e@astrojs/node\u003c/code\u003e version 11.1.3 or later immediately to incorporate the required host validation logic.\u003c/li\u003e\n\u003cli\u003eImplement strict request validation at the reverse proxy or CDN layer to block HTTP requests containing malformed \u003ccode\u003eHost\u003c/code\u003e headers or multiple port specifications.\u003c/li\u003e\n\u003cli\u003eAudit existing deployments to identify configurations utilizing \u003ccode\u003estaticHeaders: true\u003c/code\u003e, as these are at higher risk of process termination.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T04:21:27Z","date_published":"2026-10-01T04:21:27Z","id":"https://feed.craftedsignal.io/briefs/2026-10-astro-node-dos/","summary":"A vulnerability in the @astrojs/node adapter, identified as CVE-2026-102984, allows remote attackers to trigger a process crash by sending HTTP requests with malformed Host headers.","title":"Denial of Service in Astro Node Adapter via Malformed Host Header","url":"https://feed.craftedsignal.io/briefs/2026-10-astro-node-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:astro:astrojs_node:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}