CVE-2026-71314

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until MAX_VFOR_LENGTH = 100000 and crash the Nuxt process. This issue is fixed in 3.21.10 and 4.5.1.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-05 21:16

Updated : 2026-09-08 20:51


NVD link : CVE-2026-71314

Mitre link : CVE-2026-71314

CVE.ORG link : CVE-2026-71314


JSON object : View

Products Affected

No product.

CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling

CWE-789

Memory Allocation with Excessive Size Value

CWE-1284

Improper Validation of Specified Quantity in Input