What is CVE-2026-71321?
CVE-2026-71321 in Nuxt framework allows the internal `/__nuxt_island/...` endpoint to decode and hash attacker-controlled JSON body before validating the URL-resident hash. This can allow unauthenticated `POST` requests to bypass security checks, affecting versions from 3.1.0 up to 3.21.10 and 4.5.1. Immediate update is recommended.
Azərbaycanca: Nuxt çərçivəsində aşkar edilmiş CVE-2026-71321 zəifliyi `/__nuxt_island/...` daxili adlandırma nöqtəsinin URL-dəki hash-i yoxlamazdan əvvəl JSON məlumatını emal etməsi ilə bağlıdır. Bu, autentifikasiya olunmamış `POST` sorğusu vasitəsilə təhlükəsizlik mexanizmlərindən yan keçməyə imkan verə bilər. 3.1.0-dan 3.21.10-a və 4.5.1 versiyalarına qədər təsir göstərir, dərhal yeniləmə tövsiyə olunur.
FAQ2
Which internal endpoint in the Nuxt framework is affected by CVE-2026-71321?
This vulnerability affects the internal `/__nuxt_island/...` endpoint.
Which versions of Nuxt are vulnerable to CVE-2026-71321?
Versions from 3.1.0 up to 3.21.10, as well as version 4.5.1, are vulnerable.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.