CVE-2026-34404

HIGH

Nuxt OG Image vulnerable to DoS via image generation

Title source: cna
STIX 2.1

Description

Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a Denial of Service (DoS) vulnerability. The issue arises because there is no restriction on the width and height parameters of the generated image. The vulnerability was reproduced using the standard configuration and the default templates. This issue has been patched in version 6.2.5.

Scores

CVSS v3 7.5
EPSS 0.0006
EPSS Percentile 17.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (3)
npm/nuxt-og-image 0 - 6.2.5npm
nuxt/og_image < 6.2.5
nuxt-modules/og-image < 6.2.5
Published Mar 31, 2026
Tracked Since Apr 01, 2026