nuxt is vulnerable to Inefficient Algorithmic Complexity
75
High Risk
Nuxt is vulnerable to a denial-of-service (DoS) issue in its internal island renderer endpoint. An unauthenticated attacker can send oversized requests that are fully parsed and hashed before validation fails, consuming excessive CPU resources and blocking the single-threaded Nitro event loop. This can significantly degrade application performance or make the server unresponsive with a relatively low request rate.
You are affected if you are using a version that falls within the vulnerable range.
nuxt is vulnerable to Inefficient Algorithmic Complexity in versions 3.1.0 - 3.21.9 and 4.0.0 - 4.5.0.
Upgrade to a patched version. If this is not possible, enforce a strict request body size limit for the /__nuxt_island/ endpoint at the reverse proxy or edge, or disable server components if they are not required.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant