THREAT OPS › Threat News › [GHSA] GHSA-wm8w-6qjm-cv43 (high) — Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
[GHSA] GHSA-wm8w-6qjm-cv43 (high) — Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
GHSA-wm8w-6qjm-cv43 Severity: high CVE: CVE-2026-71316
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
### Impact
When a page is covered by `routeRules` `cache` / `swr` / `isr`, Nuxt enables runtime payload extraction and serves `/<page>/_payload.json`. On affected versions the renderer stored the SSR payload in the shared `cache:nuxt:pay
Indicators of compromise
- CVE-2026-71316cve
Original source: https://github.com/advisories/GHSA-wm8w-6qjm-cv43