{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/nuxt-4/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-71314"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Nuxt 3","Nuxt 4"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Nuxt"],"content_html":"\u003cp\u003eNuxt versions prior to 4.5.1 and 3.21.10 are vulnerable to a remote denial-of-service attack (CVE-2026-71314). The vulnerability originates in the island/server-component rendering pipeline, where 'v-for' directives can be applied to user-controlled props. Because the island URL hash is a predictable digest, an attacker can craft a request that forces the server-side rendering (SSR) engine to iterate a 'v-for' loop an arbitrary number of times.\u003c/p\u003e\n\u003cp\u003eBy supplying an extremely large integer as the iterated prop, an attacker causes the Nuxt server to allocate memory proportional to the iteration count, leading to an out-of-memory (OOM) crash of the worker process. The vulnerability impacts both direct 'v-for' directives on props and slot-based 'v-for' expansion via the 'vforToArray' utility. Successful exploitation requires only a small (approx. 130-byte) HTTP request. Organizations using Nuxt for SSR should update to the patched versions immediately or implement input clamping for props passed to 'v-for' within server components.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a Nuxt application using server-side rendered islands or components that perform 'v-for' iterations on user-provided props.\u003c/li\u003e\n\u003cli\u003eAttacker inspects public-facing island URL hash generation to understand the request digest format.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious request containing a crafted prop value, specifically a high-integer value intended for a 'v-for' loop.\u003c/li\u003e\n\u003cli\u003eAttacker submits the request to the target endpoint, typically targeting the /__nuxt_island/ path.\u003c/li\u003e\n\u003cli\u003eThe Nuxt SSR engine processes the request and maps the attacker-supplied integer to the 'v-for' iteration logic.\u003c/li\u003e\n\u003cli\u003eThe rendering engine expands the loop during SSR, leading to rapid, unbounded memory allocation within the worker process.\u003c/li\u003e\n\u003cli\u003eThe server process exhausts system memory and crashes, resulting in a denial-of-service for the application.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in an immediate denial-of-service condition for the targeted application instance. A single small request (approx. 130 bytes) is sufficient to crash a worker process when provided with an iteration count in the tens of millions. This allows for trivial, unauthenticated resource exhaustion and service unavailability across affected infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate to Nuxt 4.5.1 or 3.21.10 to incorporate the 'MAX_VFOR_LENGTH' clamping logic, which prevents unbounded iteration expansion.\u003c/li\u003e\n\u003cli\u003eAudit application code for components utilizing 'v-for' on props passed from server-side inputs.\u003c/li\u003e\n\u003cli\u003eDeploy manual input validation or clamping in server components using 'Math.min(count, 1000)' to provide defense-in-depth until patching is complete.\u003c/li\u003e\n\u003cli\u003eMonitor webserver logs for unusual spikes in 500-series status codes targeting the /__nuxt_island/ endpoint, which may indicate crash attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T21:25:30Z","date_published":"2026-08-05T21:25:30Z","id":"https://feed.craftedsignal.io/briefs/2026-08-nuxt-dos/","summary":"An unauthenticated remote denial-of-service vulnerability (CVE-2026-71314) in Nuxt allows attackers to trigger memory exhaustion via unbounded 'v-for' iteration within server-side rendered components.","title":"Unauthenticated Denial of Service in Nuxt SSR","url":"https://feed.craftedsignal.io/briefs/2026-08-nuxt-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Nuxt 4","version":"https://jsonfeed.org/version/1.1"}