Description
Product: Nuxt OG Image Version: 6.1.2 CWE-ID: CWE-404: Improper Resource Shutdown or Release Description: Failure to limit the length and width of the generated image results in a denial of service.
Recommendation
Update the nuxt-og-image package to the latest compatible version. Followings are version details:
- Affected version(s): < 6.2.5
- Patched version(s): 6.2.5
References
Could your website be exposed too?
SmartScanner can check your website for Nuxt OG Image is vulnerable to Denial of Service via unbounded image dimensions and gives you actionable findings to investigate.
Start a free scanRelated Issues
- ExifReader is vulnerable to denial of service via unbounded decompression of image metadata - CVE-2026-8814
- Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes - CVE-2026-34405
- jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder - CVE-2026-24133
- Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig - CVE-2026-25639


