CVE-2026-29772

Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full request body as JSON without enforcing a size limit. Because JSON.parse() allocates a V8 heap object for every element in the input, a crafted payload of many small JSON objects achieves ~15x memory amplification (wire bytes to heap bytes), allowing a single unauthenticated request to exhaust the process heap and crash the server. The /_server-islands/[name] route is registered on all Astro SSR apps regardless of whether any component uses server:defer, and the body is parsed before the island name is validated, so any Astro SSR app with the Node standalone adapter is affected. This issue has been patched in version 10.0.0.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:astro:\@astrojs\/node:*:*:*:*:*:node.js:*:*

History

17 Jun 2026, 10:29

Type Values Removed Values Added
Summary
  • (es) Astro es un framework web. Antes de la versión 10.0.0, el gestor POST de Server Islands de Astro almacena en búfer y analiza el cuerpo completo de la solicitud como JSON sin aplicar un límite de tamaño. Debido a que JSON.parse() asigna un objeto de pila V8 para cada elemento en la entrada, una carga útil manipulada de muchos objetos JSON pequeños logra una amplificación de memoria de ~15x (bytes en tránsito a bytes en pila), permitiendo que una única solicitud no autenticada agote la pila del proceso y bloquee el servidor. La ruta /_server-islands/[name] está registrada en todas las aplicaciones Astro SSR independientemente de si algún componente utiliza server:defer, y el cuerpo se analiza antes de que se valide el nombre de la isla, por lo que cualquier aplicación Astro SSR con el adaptador autónomo de Node se ve afectada. Este problema ha sido parcheado en la versión 10.0.0.

25 Mar 2026, 21:48

Type Values Removed Values Added
First Time Astro \@astrojs\/node
Astro
CPE cpe:2.3:a:astro:\@astrojs\/node:*:*:*:*:*:node.js:*:*
References () https://github.com/withastro/astro/security/advisories/GHSA-3rmj-9m5h-8fpv - () https://github.com/withastro/astro/security/advisories/GHSA-3rmj-9m5h-8fpv - Exploit, Vendor Advisory

24 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-24 19:16

Updated : 2026-06-17 10:29


NVD link : CVE-2026-29772

Mitre link : CVE-2026-29772

CVE.ORG link : CVE-2026-29772


JSON object : View

Products Affected

astro

  • \@astrojs\/node
CWE
CWE-770

Allocation of Resources Without Limits or Throttling