Vendor
high
advisory
Nuxt Ollama API Key Exposure via Public Runtime Configuration
1 TTPThe nuxt-ollama module version 1.2.26 inadvertently publishes Ollama cloud API keys in the client-side serialized runtime configuration, allowing unauthorized remote extraction via standard HTTP requests.
nuxt-ollama
credential-exposure
nuxt
ollama
misconfiguration
1t
low
advisory
Unauthenticated Denial of Service in Nuxt SSR
1 CVEAn unauthenticated remote denial-of-service vulnerability (CVE-2026-71314) in Nuxt allows attackers to trigger memory exhaustion via unbounded 'v-for' iteration within server-side rendered components.
Nuxt 3 +1
1c
high
advisory
Nuxt 4.x Runtime Payload Cache Disclosure
2 rules 3 TTPsA vulnerability in Nuxt 4.4.0 through 4.5.0 causes sensitive SSR data in the payload cache to be disclosed to unauthorized users due to an insufficient cache key implementation.
Nuxt +4
remote-code-execution
template-injection
cve-2026-71320
2r
3t
updated