CVE-2026-29772 identifies a denial-of-service vulnerability in the Astro web framework, specifically affecting Server-Side Rendered (SSR) applications utilizing the Node standalone adapter prior to version 10.0.0. An unauthenticated attacker can exploit this by sending a crafted JSON payload to the Server Islands POST handler, which, due to unbounded buffering and significant memory amplification, exhausts the server's heap and causes a crash. Rated with a CVSS score of 7.5 (HIGH), this vulnerability presents a critical availability risk with low attack complexity. Currently, there is no evidence of active exploitation, public exploit code, or notable community discussion surrounding this issue. Organizations using affected versions should upgrade to Astro 10.0.0 or later to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0.0, < 10.0.0CPE matchmatch criteria | cpe:2.3:a:astro:\@astrojs\/node:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.