Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hxcr-hm88-mpq6 | Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering |
Thu, 06 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Aug 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nuxt
Nuxt nuxt |
|
| Vendors & Products |
Nuxt
Nuxt nuxt |
Wed, 05 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until MAX_VFOR_LENGTH = 100000 and crash the Nuxt process. This issue is fixed in 3.21.10 and 4.5.1. | |
| Title | Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering | |
| Weaknesses | CWE-1284 CWE-400 CWE-770 CWE-789 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-06T13:33:38.810Z
Reserved: 2026-08-05T18:14:42.064Z
Link: CVE-2026-71314
Updated: 2026-08-06T13:33:35.382Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T22:30:05Z
Github GHSA