Junglewise Threat Intelligence

CVE-2026-41322: Astro: Cache Poisoning due to incorrect error handling when if-match header is malformed

CVE-2026-41322 · Severity: medium · CVSS 5.3 · Published 2026-04-23

Technologies: @astrojs/node (npm), Astro Node.js Adapter. Vendors: Astro, npm.

Executive brief

Astro is a web framework used to build and serve static websites and single-page applications. When an attacker sends a malformed if-match HTTP header to request static assets (CSS/JavaScript files), the framework incorrectly returns a 500 error with aggressive caching headers instead of the expected 412 error. This causes edge caches and CDNs to cache the error page for one year, breaking the website for all users until the cache expires.

Technical details

The vulnerability is a cache poisoning issue in the @astrojs/node adapter's serve-static.ts file. When the Node.js send library processes a conditional request (if-match header) and detects an ETag mismatch, it emits a 'file' event (setting forwardError = true), then a 'headers' event (which applies long-lived cache headers), and finally an 'error' event with a PreconditionFailedError (status 412). However, the error handler unconditionally calls res.writeHead(500) without inspecting the actual error status code, resulting in a 500 response with Cache-Control: public, max-age=31536000, immutable already set. The attack requires network access and no authentication; an attacker can trigger this by sending a single curl request with a malformed if-match header. The fix is available in @astrojs/node version 10.0.5 and later.

Affected products

  • Astro Astro 5.14.1
  • Astro @astrojs/node 9.4.4 and earlier; fixed in 10.0.5

Timeline

  • 2026-04-20: disclosed: Advisory published
  • 2026-04-23: patched: @astrojs/node 10.0.5 released with fix

References

Related threats