CVE-2026-71314: CVE-2026-71314: Out-of-Memory Denial of Service via Unbounded v-for Expansion in Nuxt Server Islands
CVE-2026-71314: Out-of-Memory Denial of Service via Unbounded v-for Expansion in Nuxt Server Islands Vulnerability ID: CVE-2026-71314 CVSS Score: 7.5 Published: 2026-08-05 An unauthenticated remote denial of service
CVE-2026-71314: Out-of-Memory Denial of Service via Unbounded v-for Expansion in Nuxt Server Islands
Vulnerability ID: CVE-2026-71314
CVSS Score: 7.5
Published: 2026-08-05
An unauthenticated remote denial of service (DoS) vulnerability exists in Nuxt's server component ('island') rendering mechanism. Due to a deterministic signature generation scheme and missing input constraints on server-side v-for directive expansion, an attacker can trigger unconstrained memory allocations on the hosting Node.js server, leading to immediate process crash.
TL;DR
Unauthenticated remote attackers can crash Nuxt applications via a single crafted request that exploits unbounded loop expansion in server components.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-400
- Attack Vector: Network
- CVSS Score: 7.5
- Impact: Availability (Denial of Service)
- Exploit Status: poc
- CISA KEV Status: No
Affected Systems
- Nuxt web applications utilizing Server Components (Islands)
-
Nuxt: >= 3.1.0, < 3.21.10 (Fixed in:
3.21.10) -
Nuxt: >= 4.0.0, < 4.5.1 (Fixed in:
4.5.1)
Code Analysis
Commit: 668cdfd
fix(nuxt): clamp v-for lengths in islands
Enforces MAX_VFOR_LENGTH in island template loops
Commit: 4e35ae9
fix(nuxt): apply request body limit and payload validation to server islands
Adds readGuardedIslandBody stream reader to limit body size to 64KB
Mitigation Strategies
- Upgrade Nuxt to version 3.21.10 or 4.5.1
- Disable experimental server component islands in nuxt.config.ts if unused
- Apply reverse proxy or WAF request body size limits of 64KB on island endpoints
- Implement strict rate limiting on the /__nuxt_island/ URL pattern
Remediation Steps:
- Audit package.json to identify the active Nuxt version in the project.
- Execute the update package manager command: npm install [email protected] (or yarn/pnpm equivalent).
- Verify the configuration of componentIslands in nuxt.config.ts and disable if unnecessary.
- Deploy and verify reverse proxy request restriction policies in staging prior to production push.
References
Read the full report for CVE-2026-71314 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.