<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:astro:astrojs_node:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aastroastrojs_node/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 04:21:27 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aastroastrojs_node/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service in Astro Node Adapter via Malformed Host Header</title><link>https://feed.craftedsignal.io/briefs/2026-10-astro-node-dos/</link><pubDate>Thu, 01 Oct 2026 04:21:27 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-astro-node-dos/</guid><description>A vulnerability in the @astrojs/node adapter, identified as CVE-2026-102984, allows remote attackers to trigger a process crash by sending HTTP requests with malformed Host headers.</description><content:encoded><![CDATA[<p>A vulnerability (CVE-2026-102984) exists in the <code>@astrojs/node</code> adapter (versions 11.1.2 and earlier) where improper validation of the <code>Host</code> header can lead to a denial-of-service condition. An attacker can craft a request with an invalid port specification within the <code>Host</code> header, such as <code>example.com:65536</code> or <code>example.com:8080:8080</code>. When the adapter attempts to process these requests, the logic fails to correctly generate a request URL and enters a recursive failure state. This results in an uncaught <code>TypeError: Invalid URL</code> exception. If the server is configured with <code>staticHeaders: true</code>, this exception remains unhandled, causing the entire Node.js process to terminate. This vulnerability is limited to availability disruption and does not facilitate data exfiltration or remote code execution.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability impacts applications using the <code>@astrojs/node</code> adapter, specifically those configured with the <code>staticHeaders: true</code> option, as these are susceptible to process termination. Successfully sending a crafted request to such an endpoint will crash the server, causing service downtime. Applications using the default <code>standalone</code> configuration will experience a <code>500 Internal Server Error</code> but will remain running. The attack surface is dependent on whether upstream infrastructure, such as CDNs or reverse proxies, filters malformed <code>Host</code> headers before they reach the Astro origin.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade to <code>@astrojs/node</code> version 11.1.3 or later immediately to incorporate the required host validation logic.</li>
<li>Implement strict request validation at the reverse proxy or CDN layer to block HTTP requests containing malformed <code>Host</code> headers or multiple port specifications.</li>
<li>Audit existing deployments to identify configurations utilizing <code>staticHeaders: true</code>, as these are at higher risk of process termination.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>denial-of-service</category><category>webserver</category><category>vulnerability</category></item></channel></rss>