Executive brief
Astro is a modern web framework that pre-renders certain error pages (404 and 500 errors) for performance. A vulnerability in how Astro handles HTTP requests allows an attacker to manipulate the Host header and trick the framework into fetching error pages from an attacker-controlled server, potentially exposing sensitive information. This affects self-hosted Astro SSR deployments that do not validate the Host header against allowed domains.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) caused by improper input validation in the createRequestFromNodeRequest function. While the allowedDomains configuration option exists, it only validates the X-Forwarded-For header and does not constrain the request URL origin derived from the Host header. When app.render() encounters a 404 or 500 error with a prerendered error route, it constructs the error page URL using the unconstrained origin and fetches it via prerenderedErrorPageFetch (which defaults to global fetch). An attacker can send a crafted request with a malicious Host header (e.g., Host: attacker-host:port), trigger an error by requesting a nonexistent path, and receive the attacker's response reflected back to the client. The fix validates the error page fetch origin against allowedDomains before use, falling back to localhost if the host is not validated, and wraps the fetch in error handling.
Affected products
- Astro astro <= 6.4.4
Timeline
- 2026-06-12: disclosed
- 2026-06-16: advisory
- 2026-06-16: patched: Version 6.4.6 includes the fix