


Perceptive Security
SOC/SIEM Consultancy

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop,…
Published:
4 augustus 2026 om 22:00:00
Alert date:
5 augustus 2026 om 22:02:16
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
A denial-of-service vulnerability exists in Nuxt, an open-source Vue.js web framework, affecting versions 3.1.0 through 3.21.9 and versions prior to 4.5.1. An unauthenticated attacker can exploit the server island v-for prop feature, specifically via vforToArray, to trigger unbounded server-side rendering (SSR) memory allocation. The allocation can grow up to MAX_VFOR_LENGTH of 100,000 entries, ultimately crashing the Nuxt server process. No authentication is required to trigger the vulnerability, making it easily exploitable by remote attackers. The issue has been patched in Nuxt versions 3.21.10 and 4.5.1. Fixes are available via two separate commits on the official Nuxt GitHub repository. Users are strongly advised to upgrade to the patched versions immediately to prevent potential service disruption.
Technical details
Mitigation steps:
Affected products:
Nuxt 3.1.0 - 3.21.9
Nuxt 4.x prior to 4.5.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-71314
https://github.com/nuxt/nuxt/commit/4e35ae9babd94be53246e31200232d48438bb34e
https://github.com/nuxt/nuxt/commit/668cdfdfda41849ed11c1ee5e2067a11fc103b22
https://github.com/nuxt/nuxt/releases/tag/v3.21.10
https://github.com/nuxt/nuxt/releases/tag/v4.5.1
https://github.com/nuxt/nuxt/security/advisories/GHSA-hxcr-hm88-mpq6
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
