What is CVE-2026-71316?
This CVE describes a vulnerability in the Nuxt.js framework versions 4.4.0 to 4.5.1, where the runtime cache for `/_payload.json` can bypass route middleware and page guards due to missing `import.meta.prerender` enforcement. This flaw may disclose another user's SSR data. Affected users should immediately upgrade to a version newer than 4.5.1.
Azərbaycanca: Bu CVE, Nuxt.js framework'ünün 4.4.0 ilə 4.5.1 versiyaları arasında runtime cache mexanizmindəki boşluğu təsvir edir. Zəiflik səbəbindən `/_payload.json` endpoint'ə edilən sorğularda route middleware və page guards yoxlanılmır, nəticədə başqa istifadəçilərin SSR (Server-Side Rendering) məlumatları ifşa ola bilər. Təsirə məruz qalan istifadəçilər dərhal framework'ü 4.5.1-dən yuxarı versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which Nuxt.js versions are affected by CVE-2026-71316?
This vulnerability exists in Nuxt.js framework versions 4.4.0 to 4.5.1.
What is the root cause and risk of this vulnerability?
The flaw occurs because requests to the `/_payload.json` endpoint in the runtime cache can bypass route middleware and page guards. This creates a risk of disclosing another user's SSR data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.