THREAT OPS › Threat News › [GHSA] GHSA-hxvh-4h3w-prp9 (high) — Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
[GHSA] GHSA-hxvh-4h3w-prp9 (high) — Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
GHSA-hxvh-4h3w-prp9 Severity: high CVE: CVE-2026-71315
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
### Impact
Nuxt matches route rules case-insensitively by default (mirroring vue-router's default `sensitive: false` routing). The fix for GHSA-mm7m-92g8-7m47 / CVE-2026-53721 lowercased the *lookup* path before mat
Indicators of compromise
- CVE-2026-53721cve
- CVE-2026-71315cve
Original source: https://github.com/advisories/GHSA-hxvh-4h3w-prp9