Junglewise Threat Intelligence

CVE-2026-27729: Astro memory exhaustion DoS in Server Actions

CVE-2026-27729 · Severity: low · CVSS 3.1 · Published 2026-02-25

Technologies: @astrojs/node (npm). Vendors: Astro, npm.

Executive brief

Astro's Server Actions feature lacks request body size limits, allowing attackers to crash web application servers by sending oversized POST requests. This vulnerability affects web applications built with Astro that use server-side rendering (SSR) in standalone deployment mode. An unauthenticated attacker can repeatedly trigger server crashes, causing service outages and business disruption in containerized environments where the process automatically restarts in a crash loop.

Technical details

This vulnerability is an unrestricted resource allocation (CWE-770) affecting Astro's Server Actions framework. The root cause is the absence of default request body size limits in the Node adapter's standalone mode; incoming JSON and FormData request bodies are buffered entirely into memory without validation. An unauthenticated attacker can exploit this by sending a single POST request with a payload exceeding the process heap size to the discoverable action endpoint (e.g., /_actions/echo), causing an out-of-memory heap allocation failure and process crash. No authentication or user interaction is required; action names are publicly discoverable from HTML form attributes. The attack is network-reachable with high complexity (requires knowledge of heap constraints), but results in complete availability loss. Patch available in @astrojs/node version 9.5.4 and later.

Affected products

  • Astro Node adapter (@astrojs/node) 9.0.0 to 9.5.3

Timeline

  • 2026-02-25: disclosed: GitHub Security Advisory GHSA-jm64-8m5q-4qh8 published
  • 2026-02-25: patched: Fix available in @astrojs/node 9.5.4+

References

Related threats