Nuxt released version 4.5.1 with urgent fixes for multiple security flaws affecting server-side rendering, server islands, and runtime caching. The patched issues include CVE-2026-71314 and CVE-2026-71321, which allow unauthenticated attackers to trigger denial-of-service conditions through the internal /__nuxt_island/ endpoint by forging or sending expensive island rendering requests, exhausting CPU during request-body parsing and hashing, or forcing massive v-for expansions that can crash Node.js with out-of-memory errors. Nuxt added protections including request validation hardening, body-size and parsing guards, and a MAX_VFOR_LENGTH bound to limit server-side loop expansion.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Alongside the security release, Nuxt advised users employing cache, swr, or isr route rules to purge CDN or edge caches after upgrading. The project warned that leaked _payload.json files might already be cached upstream.
The v4.5.1 release introduced a change to reject a top-level "as" prop in server island requests. This mitigated unauthorized component instantiation through Vue attribute fallthrough in island rendering.
The v4.5.1 release added bounds on island props and v-for processing to mitigate unauthenticated denial-of-service conditions in the /__nuxt_island/ handler. The mitigations include guarded body handling, structural checks, and limiting oversized numeric iteration ranges.
As part of the v4.5.1 release, Nuxt changed payload caching so cached payloads are used only in prerendering contexts, disabling runtime payload caching otherwise. This addressed the cross-user payload disclosure issue later tracked as CVE-2026-71316.
Nuxt published version 4.5.1 as a security release and urged users to upgrade immediately. The release fixes multiple vulnerabilities, including unauthorized component instantiation via server island props, server component denial of service, cross-user payload disclosure on cached pages, and other issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvereports.com
Open sourcecvereports.com
Open sourcecvereports.com
Open sourcegithub.com
Open sourcenuxt.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.