


Perceptive Security
SOC/SIEM Consultancy

Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can be returne…
Published:
5 augustus 2026 om 00:00:00
Alert date:
6 augustus 2026 om 01:01:32
Source:
nvd.nist.gov
Web Technologies
A vulnerability in the Nuxt open-source Vue.js web framework (versions 4.4.0 to 4.5.1) allows runtime cache entries for payload JSON files to be returned before route middleware and page guards are enforced. This occurs because import.meta.prerender is not properly enforced, leading to potential disclosure of another user's server-side rendering (SSR) data. The flaw could expose sensitive user information across sessions in affected deployments. The issue has been assigned CVE-2026-71316 and is classified as an information disclosure vulnerability. A fix was released in Nuxt version 4.5.1. Users running affected versions are advised to upgrade immediately to mitigate the risk of cross-user data leakage.
Technical details
Mitigation steps:
Affected products:
Nuxt 4.4.0
Nuxt 4.5.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-71316
https://github.com/nuxt/nuxt/commit/ac9b41a36b62296a117862254ee7d2b21a2a5203
https://github.com/nuxt/nuxt/releases/tag/v4.5.1
https://github.com/nuxt/nuxt/security/advisories/GHSA-wm8w-6qjm-cv43
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
