THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hxvh-4h3w-prp9 (high) — Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)

[GHSA] GHSA-hxvh-4h3w-prp9 (high) — Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)

medgithub_advisoriesPublished 2026-08-05

GHSA-hxvh-4h3w-prp9 Severity: high CVE: CVE-2026-71315

Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)

### Impact

Nuxt matches route rules case-insensitively by default (mirroring vue-router's default `sensitive: false` routing). The fix for GHSA-mm7m-92g8-7m47 / CVE-2026-53721 lowercased the *lookup* path before mat

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hxvh-4h3w-prp9