How to use this reference
The advisory identifies 4.5.1 as fixed by limiting shared payload caching to prerendering and restoring runtime authorization. Official release notes corroborate the fix and recommend clearing upstream caches. Editorial lesson: treat each rendered representation as a separate disclosure boundary; correct HTML protection does not prove data-response protection.
Before reading
- Server-side rendering and client data hydration
- Cache partitioning and request authorization
Context and limits
- Exposure requires affected Nuxt 4.4.0–4.5.0, cached routes with runtime payload extraction, and user-specific server-rendered data. Nuxt 3.x is excluded by the advisory.
- The advisory credits quantumshiro as finder; danielroe is the publishing maintainer.
- No production incident or bounty amount established. Learning prerequisites and generalized review guidance are editorial.
- The software-release page displays July 27 without a year in the retrieved rendering. No exact software-release date is inferred; advisory publication is independently explicit.
Sources and provenance
- Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients Nuxt · reviewed 2026-10-03
- Nuxt v4.5.1 release Nuxt · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.