Description
By sending a crafted HTTP request to a server behind an CDN, it is possible in some circumstances to poison the CDN cache and highly impacts the availability of a site.
It is possible to craft a request, such as https://mysite.com/?/_payload.json
which will be rendered as JSON.
Recommendation
Update the nuxt
package to the latest compatible version. Followings are version details:
- Affected version(s): >= 3.0.0, < 3.16.0
- Patched version(s): 3.16.0
References
Related Issues
- Finance.js vulnerable to DoS via the IRR function’s depth parameter - CVE-2025-56571
- MetaMask SDK indirectly exposed via malicious [email protected] dependency - Vulnerability
- Mermaid improperly sanitizes sequence diagram labels leading to XSS - CVE-2025-54881
- Payload does not invalidate JWTs after log out (GHSA-5v66-m237-hwf7) - CVE-2025-4643
- Tags:
- npm
- nuxt
Anything's wrong? Let us know Last updated on March 20, 2025