The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @nuxt/nitro-server to version 3.21.10, 4.5.1 or higher.
@nuxt/nitro-server is a Nitro server integration for Nuxt
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the island renderer endpoint when attacker-controlled input is decoded and hashed before URL-resident hash validation. An attacker can exhaust CPU resources and degrade or stall the server by sending large, deeply nested JSON payloads to the endpoint, causing the server to process and reject the request only after significant computation.
Note: This is only exploitable if the server is accessible to unauthenticated users and does not enforce request body size or nesting depth limits.
This vulnerability can be mitigated by placing a small request-body limit in front of /__nuxt_island/ at your reverse proxy or edge, or by disabling server components if unused.