{"id":"GHSA-hxcr-hm88-mpq6","summary":"Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering","details":"### Impact\n\nAn unauthenticated attacker can crash a Nuxt server that renders any island / server component containing a `v-for` over a prop (for example `v-for=\"n in count\"` or a `\u003cslot v-for\u003e`). Because the island URL hash is a non-secret digest of the request, the attacker can compute a valid hash for arbitrary props and send the iterated prop as a large integer. The server then expands the `v-for` to that many nodes during SSR, allocating memory proportional to the attacker's number. Reporter figures: `count=8000000` produced a 142.9 MB response; `count=40000000` (and `items=4000000` on a slot list) produced an out-of-memory crash of the worker from a single ~130-byte request. Both the plain `v-for` path (Vue's `ssrRenderList`) and the slot path (`vforToArray`) are affected.\n\n### Patches\n\nFixed in `nuxt@4.5.1` and `nuxt@3.21.10`. Island/server-component `v-for` sources are now clamped to a maximum iteration count (`MAX_VFOR_LENGTH = 100000`) at the render boundary, covering the plain path, the `\u003cslot v-for\u003e` element, and the `vforToArray` slot-props helper. Combined with the body-size cap (GHSA-9pgf-384g-p7mv), a single island render can no longer allocate without bound regardless of which `v-for` path is used or whether the prop arrives as an integer or an array.\n\n### Workarounds\n\nAvoid `v-for` directly over an unclamped prop in server components, or clamp the count in the component (`v-for=\"n in Math.min(count, 1000)\"`). A body-size limit in front of `/__nuxt_island/` only mitigates array-shaped inputs, not the integer-amplification case.\n\n### References\n\n- Bound helper: `packages/nuxt/src/app/components/vfor.ts`\n- Transform: `packages/nuxt/src/components/plugins/islands-transform.ts`\n- Slot helper: `packages/nuxt/src/app/components/utils.ts` (`vforToArray`)","aliases":["CVE-2026-71314"],"modified":"2026-08-05T21:26:13.030639Z","published":"2026-08-05T20:59:04Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-1284","CWE-400","CWE-770","CWE-789"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-08-05T20:59:04Z"},"references":[{"type":"WEB","url":"https://github.com/nuxt/nuxt/security/advisories/GHSA-hxcr-hm88-mpq6"},{"type":"WEB","url":"https://github.com/nuxt/nuxt/commit/4e35ae9babd94be53246e31200232d48438bb34e"},{"type":"WEB","url":"https://github.com/nuxt/nuxt/commit/668cdfdfda41849ed11c1ee5e2067a11fc103b22"},{"type":"PACKAGE","url":"https://github.com/nuxt/nuxt"},{"type":"WEB","url":"https://github.com/nuxt/nuxt/releases/tag/v3.21.10"},{"type":"WEB","url":"https://github.com/nuxt/nuxt/releases/tag/v4.5.1"}],"affected":[{"package":{"name":"nuxt","ecosystem":"npm","purl":"pkg:npm/nuxt"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.5.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-hxcr-hm88-mpq6/GHSA-hxcr-hm88-mpq6.json"}},{"package":{"name":"nuxt","ecosystem":"npm","purl":"pkg:npm/nuxt"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.1.0"},{"fixed":"3.21.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-hxcr-hm88-mpq6/GHSA-hxcr-hm88-mpq6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}