THREAT OPS › Threat News › [GHSA] GHSA-9pgf-384g-p7mv (high) — Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
[GHSA] GHSA-9pgf-384g-p7mv (high) — Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
GHSA-9pgf-384g-p7mv Severity: high CVE: CVE-2026-71321
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
### Impact
The internal island renderer endpoint (`/__nuxt_island/...`) decodes and hashes attacker-controlled request input before it validates the URL-resident hash. An unauthenticated `POST /__nuxt_island/<name>_<anything>.json`
Indicators of compromise
- CVE-2026-71321cve
Original source: https://github.com/advisories/GHSA-9pgf-384g-p7mv