{"id":"CVE-2026-71314","title":"Nuxt is an open-source web development framework for Vue.js","summary":"Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-400","CWE-770","CWE-789","CWE-1284"],"vendor":"nuxt","product":"nuxt","affected":["nuxt >= 4.0.0, < 4.5.1","nuxt >= 3.1.0, < 3.21.10"],"patched":["nuxt 4.5.1","nuxt 3.21.10"],"published":"2026-08-05","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:51:43.490","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-71314","references":[{"url":"https://github.com/nuxt/nuxt/commit/4e35ae9babd94be53246e31200232d48438bb34e","label":"security-advisories@github.com"},{"url":"https://github.com/nuxt/nuxt/commit/668cdfdfda41849ed11c1ee5e2067a11fc103b22","label":"security-advisories@github.com"},{"url":"https://github.com/nuxt/nuxt/releases/tag/v3.21.10","label":"security-advisories@github.com"},{"url":"https://github.com/nuxt/nuxt/releases/tag/v4.5.1","label":"security-advisories@github.com"},{"url":"https://github.com/nuxt/nuxt/security/advisories/GHSA-hxcr-hm88-mpq6","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-hxcr-hm88-mpq6"}],"tags":["nvd","ghsa","npm"],"epss":0.004,"epssPercentile":0.33972,"aliases":["GHSA-hxcr-hm88-mpq6"],"ecosystem":"npm","ingestedAt":"2026-08-05T21:52:35.883Z","slug":"CVE-2026-71314","body":"## Overview\n\nNuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until MAX_VFOR_LENGTH = 100000 and crash the Nuxt process. This issue is fixed in 3.21.10 and 4.5.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-71314)\n\nAffected packages:\n\n- `nuxt >= 4.0.0, < 4.5.1`\n- `nuxt >= 3.1.0, < 3.21.10`\n\nPatched in:\n\n- `nuxt 4.5.1`\n- `nuxt 3.21.10`\n\nSource: https://github.com/advisories/GHSA-hxcr-hm88-mpq6","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}