What is CVE-2026-71314?
This vulnerability in Nuxt.js allows an unauthenticated attacker to trigger unbounded SSR memory allocation via the 'v-for' directive in server islands, causing the process to crash. Affected versions are from 3.1.0 to 3.21.10 and 4.5.1; users should immediately update to a patched version.
Azərbaycanca: Bu boşluq Nuxt.js framework-də server tərəfində render (SSR) zamanı "v-for" direktivindən istifadə edərək autentifikasiya olunmamış hücumçuya limitsiz yaddaş tələb etməyə imkan verir ki, bu da prosesi çökdürür. Təsirə məruz qalan versiyalar 3.1.0-3.21.10 və 4.5.1 arasıdır; istifadəçilər dərhal yeniləmə tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ1
Which Nuxt.js feature does CVE-2026-71314 exploit?
This vulnerability allows an unauthenticated attacker to trigger unbounded SSR memory allocation via the 'v-for' directive in server islands.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.