Astro · Astro · CVE-2026-102984
**Name of the Vulnerable Software and Affected Versions**
Astro versions prior to 11.1.3
**Description**
The @astrojs/node adapter constructs a request URL using the `Host` header. A malformed port within this header can result in an invalid URL. The recovery process then reuses this malformed host, triggering an uncaught `TypeError: Invalid URL` before routing occurs. In the default standalone configuration, this results in an HTTP 500 response. However, if `staticHeaders` is enabled, the synchronous handler fails to catch the exception, causing the Node process to terminate. This issue impacts availability and does not allow for data exposure or code execution.
**Recommendations**
Update to version 11.1.3.