CVE-2026-34404
Last modified
CVE-2026-34404 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a Denial of Service (DoS) vulnerability. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a Denial of Service (DoS) vulnerability. The issue arises because there is no restriction on the width and height parameters of the generated image. The vulnerability was reproduced using the standard configuration and the default templates. This issue has been patched in version 6.2.5.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nuxt | Og Image | < 6.2.5 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-34404?
How severe is CVE-2026-34404?
How do I fix CVE-2026-34404?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-34398FreeCAD is a free and open-source multiplatform 3D parametri…7.8
- CVE-2026-34399FreeCAD is a free and open-source multiplatform 3D parametri…7.8
- CVE-2026-34400Alerta is a monitoring tool. Prior to version 9.1.0, the Que…9.8
- CVE-2026-34401XML Notepad is a Windows program that provides a simple intu…6.5
- CVE-2026-34402Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-34403Nginx UI is a web user interface for the Nginx web server. P…8.1
- CVE-2026-34405Nuxt OG Image generates OG Images with Vue templates in Nuxt…6.1
- CVE-2026-34406APTRS (Automated Penetration Testing Reporting System) is a …8.8
- CVE-2026-34408An issue was discovered in Gambio 4.9.2.0 (patched in 2024-0…9.1
- CVE-2026-3441A flaw was found in GNU Binutils. This heap-based buffer ove…7.1
- CVE-2026-34411Appsmith versions prior to 1.98 expose sensitive instance ma…6.9
- CVE-2026-34412Rejected reason: This CVE ID has been rejected or withdrawn …
Are you affected by CVE-2026-34404?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
