Nuxt disclosed CVE-2026-71315, a high-severity authorization bypass caused by route rules not matching correctly when applications use case-insensitive routing. In affected versions 3.21.7 through before 3.21.10 and 4.4.7 through before 4.5.1, mixed-case routeRules keys could be silently dropped when router.options.sensitive was false, allowing appMiddleware protections and other path-based controls to fail on differently cased requests. The issue was recorded as an incomplete fix for CVE-2026-53721 and was mapped to CWE-178 and CWE-863.
Nuxt fixed the bug by adding both case-sensitive and case-folded route-rule matchers, selecting behavior at runtime based on router sensitivity, and updating prerender and manifest handling so mixed-case keys are applied consistently. The vendor shipped the remediation in Nuxt 3.21.10 and 4.5.1, alongside tests covering middleware, redirects, SSR, and prerender behavior across request casing, and said users who previously upgraded for the earlier advisory still need this release because the prior route-rule fix introduced a regression. The v3.21.10 security release also bundled fixes for additional issues, including server-side RCE, unauthorized server-island component instantiation, server component denial of service, and development server path disclosure.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
GitHub advisory references for CVE-2026-71315 were published, pointing to the Nuxt fix commits and remediated releases 3.21.10 and 4.5.1. The advisory described the flaw as mixed-case routeRules keys failing to match case-folded lookups when `router.options.sensitive` is false, allowing appMiddleware authorization gates to be dropped.
The CVE record for CVE-2026-71315 was newly received by security-advisories@github.com. The advisory documented a Nuxt vulnerability affecting versions 3.21.7 through before 3.21.10 and 4.4.7 through before 4.5.1, caused by an incomplete fix for CVE-2026-53721.
Nuxt published security release v3.21.10 and urged users to upgrade immediately. The release fixed multiple vulnerabilities, including the route rule authorization bypass, and noted that users who had already upgraded for CVE-2026-53721 still needed this release because one fix addressed a regression from the earlier advisory.
Nuxt committed code changes to fix route-rules matching when routing is case-insensitive, addressing cases where mixed-case routeRules keys could silently fail and drop protections such as appMiddleware, redirects, SSR, or prerender behavior. The patch added folded and case-sensitive matchers, updated manifest and prerender logic, and introduced tests covering mixed-case and sensitive-routing behavior.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.