What is CVE-2026-71315?
A case-sensitivity flaw in Nuxt.js routeRules allows mixed-case keys to bypass appMiddleware authorization gates when router.options.sensitive is false. This is an incomplete fix for CVE-2026-53721, affecting versions 3.21.7 to 3.21.10 and 4.5.1. Users should upgrade immediately to patched versions.
Azərbaycanca: Nuxt.js framework-də routeRules üçün hərf həssaslığı problemi aşkarlanıb. Zərərli şəxs qarışıq registrli açarlarla 'appMiddleware' icazə yoxlamalarını keçə bilər. İstifadəçilər dərhal 3.21.10 və ya 4.5.1-dən yuxarı versiyalara yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What issue does CVE-2026-71315 cause in Nuxt.js?
The vulnerability causes a case-sensitivity flaw in routeRules, allowing an attacker to bypass appMiddleware authorization gates using mixed-case keys.
What action should be taken to mitigate CVE-2026-71315?
Users should immediately upgrade to versions above 3.21.10 or 4.5.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.