Description

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until MAX_VFOR_LENGTH = 100000 and crash the Nuxt process. This issue is fixed in 3.21.10 and 4.5.1.

Severity (CVSS)

Base score7.5
SeverityHigh
VersionCVSS 3.1
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Provided byCNA

Weaknesses

  • CWE-400 — CWE-400: Uncontrolled Resource Consumption
  • CWE-770 — CWE-770: Allocation of Resources Without Limits or Throttling
  • CWE-789 — CWE-789: Memory Allocation with Excessive Size Value
  • CWE-1284 — CWE-1284: Improper Validation of Specified Quantity in Input

Affected products

VendorProductVersions
nuxtnuxt>= 4.0.0, < 4.5.1; >= 3.1.0, < 3.21.10

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 06 Aug 2026 07:06 UTC.