CVE-2026-71314: Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering

Published Aug 5, 2026
·
Updated

Impact

An unauthenticated attacker can crash a Nuxt server that renders any island / server component containing a v-for over a prop (for example v-for="n in count" or a <slot v-for>). Because the island URL hash is a non-secret digest of the request, the attacker can compute a valid hash for arbitrary props and send the iterated prop as a large integer. The server then expands the v-for to that many nodes during SSR, allocating memory proportional to the attacker's number. Reporter figures: count=8000000 produced a 142.9 MB response; count=40000000 (and items=4000000 on a slot list) produced an out-of-memory crash of the worker from a single ~130-byte request. Both the plain v-for path (Vue's ssrRenderList) and the slot path (vforToArray) are affected.

Patches

Fixed in nuxt@4.5.1 and nuxt@3.21.10. Island/server-component v-for sources are now clamped to a maximum iteration count (MAXVFORLENGTH = 100000) at the render boundary, covering the plain path, the <slot v-for> element, and the vforToArray slot-props helper. Combined with the body-size cap (GHSA-9pgf-384g-p7mv), a single island render can no longer allocate without bound regardless of which v-for path is used or whether the prop arrives as an integer or an array.

Workarounds

Avoid v-for directly over an unclamped prop in server components, or clamp the count in the component (v-for="n in Math.min(count, 1000)"). A body-size limit in front of /nuxtisland/ only mitigates array-shaped inputs, not the integer-amplification case.

References

- Bound helper: packages/nuxt/src/app/components/vfor.ts - Transform: packages/nuxt/src/components/plugins/islands-transform.ts - Slot helper: packages/nuxt/src/app/components/utils.ts (vforToArray)

Other sources

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until MAXVFORLENGTH = 100000 and crash the Nuxt process. This issue is fixed in 3.21.10 and 4.5.1.

MITRE

Affected Software

2 affected componentsFixes available
npm/nuxt>=3.1.0<3.21.10
3.21.10
npm/nuxt>=4.0.0<4.5.1
4.5.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/nuxt to a version that resolves this vulnerability.

    Fixed in 3.21.10
  2. Upgrade

    Upgrade npm/nuxt to a version that resolves this vulnerability.

    Fixed in 4.5.1
  3. Upgrade

    Upgrade nuxt to a version that resolves this vulnerability.

    Fixed in 4.5.1
  4. Upgrade

    Upgrade nuxt to a version that resolves this vulnerability.

    Fixed in 3.21.10
  5. Configuration

    Ensure Nuxt clamps island/server-component v-for iteration counts to MAX_VFOR_LENGTH = 100000 at the render boundary (covers plain v-for path, <slot v-for>, and the vforToArray slot-props helper).

    Nuxt island/server-component v-for render boundary MAX_VFOR_LENGTH = 100000
  6. Configuration

    Avoid using `v-for` directly over an unclamped prop in server components; clamp the count at the component (e.g., `v-for="n in Math.min(count, 1000)"`).

    Nuxt island/server components v-for over props = clamp
  7. Compensating control

    Use a body-size limit in front of `/__nuxt_island/` (GHSA-9pgf-384g-p7mv mitigates array-shaped inputs, but does not address the integer-amplification case by itself).

Event History

Aug 5, 2026
CVE Published
via MITRE·08:58 PM
Data Sourced
via MITRE·08:58 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·08:59 PM
Data Sourced
via GitHub·08:59 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203