GHSA-qh8j-hqjv-7m4x

Suggest an improvement
Source
https://github.com/advisories/GHSA-qh8j-hqjv-7m4x
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-qh8j-hqjv-7m4x/GHSA-qh8j-hqjv-7m4x.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qh8j-hqjv-7m4x
Aliases
Published
2026-09-30T23:29:40Z
Modified
2026-09-30T23:45:04Z
Severity
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Astro: Malformed port in the Host header can crash the Node adapter
Details

Summary

In the Astro Node adapter, a request whose Host header contains a malformed port (for example example.com:65536 or example.com:8080:8080) produced an invalid request URL. The fallback intended to recover from an unparseable URL reused the same malformed host, so it failed again and raised an uncaught TypeError: Invalid URL while the request was being built, before any route ran.

Impact

The effect depends on the adapter configuration:

  • Default configuration (standalone): the request returns 500 Internal Server Error and the server continues running.
  • With the opt-in staticHeaders: true option: the throw reaches a synchronous HTTP handler that does not catch it, becoming an uncaughtException that terminates the process.

This is an availability-only issue. It does not expose data or allow code execution. Triggering it requires sending a hand-crafted Host header, and many proxies and CDNs reject malformed hosts before they reach the origin.

Affected versions

@astrojs/node <= 11.1.2.

Patches

Fixed in @astrojs/node 11.1.3. When the incoming host cannot be parsed, the request URL now degrades to a host the server controls, so the request is handled instead of throwing. Hosts carrying more than a single hostname:port pair are also rejected during host validation.

Workarounds

Upgrade to @astrojs/node 11.1.3 or later. Deployments that terminate malformed Host headers at a reverse proxy or CDN are not reachable through this path.

Credits

Reported by @Celggar.

Database specific
{
    "cwe_ids":  [
        "CWE-248"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-30T23:29:40Z",
    "nvd_published_at":  "2026-09-30T15:22:23Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / @astrojs/node

Package

Name
@astrojs/node
View open source insights on deps.dev
Purl
pkg:npm/%40astrojs/node

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
11.1.3

Database specific

last_known_affected_version_range
"<= 11.1.2"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-qh8j-hqjv-7m4x/GHSA-qh8j-hqjv-7m4x.json"