CVE-2026-71316

Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can be returned before route middleware and page guards because import.meta.prerender is not enforced, disclosing another user's SSR data. This issue is fixed in 4.5.1.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-05 22:17

Updated : 2026-09-08 20:51


NVD link : CVE-2026-71316

Mitre link : CVE-2026-71316

CVE.ORG link : CVE-2026-71316


JSON object : View

Products Affected

No product.

CWE
CWE-524

Use of Cache Containing Sensitive Information

CWE-862

Missing Authorization