Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-34404

Опубликовано: 31 мар. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a Denial of Service (DoS) vulnerability. The issue arises because there is no restriction on the width and height parameters of the generated image. The vulnerability was reproduced using the standard configuration and the default templates. This issue has been patched in version 6.2.5.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nuxt:og_image:*:*:*:*:*:node.js:*:*
Версия до 6.2.5 (исключая)

EPSS

Процентиль: 25%
0.00324
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

github
4 месяца назад

Nuxt OG Image is vulnerable to Denial of Service via unbounded image dimensions

CVSS3: 5.3
fstec
5 месяцев назад

Уязвимость компонента /_og/d/ модуля генерации Open Graph (OG) изображений Nuxt OG Image фреймворка для создания веб-приложений и сайтов Nuxt.js, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 25%
0.00324
Низкий

7.5 High

CVSS3

Дефекты

CWE-400