THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9pgf-384g-p7mv (high) — Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation

[GHSA] GHSA-9pgf-384g-p7mv (high) — Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation

medgithub_advisoriesPublished 2026-08-05

GHSA-9pgf-384g-p7mv Severity: high CVE: CVE-2026-71321

Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation

### Impact

The internal island renderer endpoint (`/__nuxt_island/...`) decodes and hashes attacker-controlled request input before it validates the URL-resident hash. An unauthenticated `POST /__nuxt_island/<name>_<anything>.json`

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9pgf-384g-p7mv