CVE-2026-29772Disclosure(astro / \@astrojs\/node)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full request body as JSON without enforcing a size limit. Because JSON.parse() allocates a V8 heap object for every element in the input, a crafted payload of many small JSON objects achieves ~15x memory amplification (wire bytes to heap bytes), allowing a single unauthenticated request to exhaust the process heap and crash the server. The /_server-islands/[name] route is registered on all Astro SSR apps regardless of whether any component uses server:defer, and the body is parsed before the island name is validated, so any Astro SSR app with the Node standalone adapter is affected. This issue has been patched in version 10.0.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • \@astrojs\/node

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-24); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
\@astrojs\/node

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-24: 1Mentions · 2026-03-27: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-27: 103-2403-27
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • AISafe Labs@aisafe_io
    Disclosure

    CVE-2026-29772: Memory DoS in Astro Server Islands https://aisafe.io/blog/cve-2026-29772-astro-dos-server-islands

    Post summary

    The post announces a memory denial‑of‑service vulnerability (CVE‑2026‑29772) in Astro Server Islands, without providing proof‑of‑concept, exploit code, or active exploitation details.

    040105622
    69 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-29772 - Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands Intel Report: https://ift.tt/XSnakK8

    Post summary

    A new CVE-2026-29772 vulnerability in Astro allows memory‑exhaustion denial‑of‑service attacks by omitting request body size limits, with an Intel report linked for more information.

    0001148
    286 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appastro\@astrojs\/node-node.js-

Explore more