CVE-2026-71321: Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_island/...` decodes and hashes attac
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint /__nuxt_island/... decodes and hashes attacker-controlled JSON body input with destr and ohash before validating the URL-resident hash. An unauthenticated POST /__nuxt_island/_.json with a large JSON body is fully read, parsed, hashed, and then rejected, which wastes CPU on Nitro single event loop and delays concurrent requests. No valid hash and no authentication are required. This issue is fixed in 3.21.10 and 4.5.1.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-71321
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-713210.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-71321 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Nuxt is an
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-71320: Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.…nvd · 2026-08-05
- criticalCVE-2026-71319: Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (de…nvd · 2026-08-05
- mediumCVE-2026-71318: Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.…nvd · 2026-08-05
- highCVE-2026-71316: Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime c…nvd · 2026-08-05
- highGHSA-9pgf-384g-p7mv: Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body be…ghsa · 2026-08-05
- highGHSA-9473-5f9j-94wq: Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Isl…ghsa · 2026-08-05
More from NVD Recent CVEs
- highCVE-2026-19190: A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part …2026-08-07
- unknownCVE-2026-49746: Software installed and run as a non-privileged user may conduct improper GPU system calls to c…2026-08-07
- unknownCVE-2026-45204: Software installed and run as a non-privileged user may conduct improper GPU system calls to t…2026-08-07
- unknownCVE-2026-45198: Kernel software from a non-secure operating system on a platform with Trusted Execution Enviro…2026-08-07
- highCVE-2026-19189: A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue …2026-08-07