Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @astrojs/node
  4. ›
  5. CVE-2026-27729

CVE-2026-27729: Astro has memory exhaustion DoS due to missing request body size limit in Server Actions

February 25, 2026

Astro server actions have no default request body size limit, which can lead to memory exhaustion DoS. A single large POST to a valid action endpoint can crash the server process on memory-constrained deployments.

References

  • github.com/advisories/GHSA-jm64-8m5q-4qh8
  • github.com/withastro/astro
  • github.com/withastro/astro/commit/522f880b07a4ea7d69a19b5507fb53a5ed6c87f8
  • github.com/withastro/astro/pull/15564
  • github.com/withastro/astro/releases/tag/@astrojs/node@9.5.4
  • github.com/withastro/astro/security/advisories/GHSA-jm64-8m5q-4qh8
  • nvd.nist.gov/vuln/detail/CVE-2026-27729

Code Behaviors & Features

Detect and mitigate CVE-2026-27729 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 9.0.0 before 9.5.4

Fixed versions

  • 9.5.4

Solution

Upgrade to version 9.5.4 or above.

Impact 5.9 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-770: Allocation of Resources Without Limits or Throttling

Source file

npm/@astrojs/node/CVE-2026-27729.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 26 Feb 2026 12:18:00 +0000.