CVE-2026-71315

HIGH

Nuxt 3.21.7-3.21.9 and 4.4.7-4.5.0 - appMiddleware Auth Bypass

Title source: manual
STIX 2.1

Description

Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded lookups when router.options.sensitive is false and drop appMiddleware authorization gates. This is caused by an incomplete fix for CVE-2026-53721. This issue is fixed in 3.21.10 and 4.5.1.

Scores

CVSS v3 8.2
EPSS 0.0027
EPSS Percentile 18.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-178 CWE-863
Status published
Products (4)
npm/nuxt 3.21.7 - 3.21.10npm
npm/nuxt 4.4.7 - 4.5.1npm
nuxt/nuxt >= 3.21.7, < 3.21.10
nuxt/nuxt >= 4.4.7, < 4.5.1
Published Aug 05, 2026
Tracked Since Aug 06, 2026