CVE-2026-102984: Astro: Malformed port in the Host header can crash the Node adapter
In the Astro Node adapter, a request whose Host header contains a malformed port (for example example.com:65536 or example.com:8080:8080) produced an invalid request URL. The fallback intended to recover from an unparseable URL reused the same malformed host, so it failed again and raised an uncaught TypeError: Invalid URL while the request was being built, before any route ran.
References
- github.com/advisories/GHSA-qh8j-hqjv-7m4x
- github.com/withastro/astro/commit/2066f39c60707a100531b4ef4bb5dab8feafa7f2
- github.com/withastro/astro/pull/17572
- github.com/withastro/astro/releases/tag/@astrojs/node@11.1.3
- github.com/withastro/astro/security/advisories/GHSA-qh8j-hqjv-7m4x
- nvd.nist.gov/vuln/detail/CVE-2026-102984
Code Behaviors & Features
Detect and mitigate CVE-2026-102984 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →