CVE-2026-71315: Nuxt

High severity, CVSS 8.2. EPSS: 0.5% chance of exploitation in the next 30 days.

Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded lookups when router.options.sensitive is false and drop appMiddleware authorization gates. This is caused by an incomplete fix for CVE-2026-53721. This issue is fixed in 3.21.10 and 4.5.1.

Affected products

  • Nuxt Nuxt: from 4.4.7, before 4.5.1 (fixed in 4.5.1); from 3.21.7, before 3.21.10 (fixed in 3.21.10)

Published 2026-08-05. Last modified 2026-09-08.