Vulnerability Description
Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can be returned before route middleware and page guards because import.meta.prerender is not enforced, disclosing another user's SSR data. This issue is fixed in 4.5.1.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/nuxt/nuxt/commit/ac9b41a36b62296a117862254ee7d2b21a2a5203
- https://github.com/nuxt/nuxt/releases/tag/v4.5.1
- https://github.com/nuxt/nuxt/security/advisories/GHSA-wm8w-6qjm-cv43
FAQ
What is CVE-2026-71316?
CVE-2026-71316 is a vulnerability with a CVSS score of 7.5 (HIGH). Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can be returned before route middleware and page guard...
How severe is CVE-2026-71316?
CVE-2026-71316 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-71316?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.