PT-2026-29370 · Nuxt · Nuxt Og Image

·

CVE-2026-34404

·

Published

2026-03-26

·

Updated

2026-04-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Nuxt OG Image versions prior to 6.2.5
Description The Nuxt OG Image component, used for generating Open Graph images with Vue templates in Nuxt, contains a potential for Denial of Service (DoS). This issue stems from a lack of restrictions on the width and height parameters when generating images via the /og/d/ endpoint (and /og-image/ in older versions). Sending a request with excessively large width and height values can exhaust server resources during image generation, leading to a DoS condition. The vulnerability was demonstrated by sending a GET request to the /og/d/og.png API endpoint with increased width and height parameters, such as width=20000&height=20000. This caused memory exhaustion on the test server.
Recommendations Versions prior to 6.2.5: Implement a limitation on the width and length of the generated image.

Exploit

Fix

Improper Resource Release

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05337
CVE-2026-34404
GHSA-C7XP-Q6Q8-HG76

Affected Products

Nuxt Og Image