{"id":"GHSA-hxvh-4h3w-prp9","summary":"Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)","details":"### Impact\n\nNuxt matches route rules case-insensitively by default (mirroring vue-router's default `sensitive: false` routing). The fix for GHSA-mm7m-92g8-7m47 / CVE-2026-53721 lowercased the *lookup* path before matching route rules, but the route-rule *keys* compiled into the matcher were left verbatim. As a result, any route rule whose key contains an uppercase character (for example `/Admin`, `/Dashboard/**`, or the rules Nuxt derives from PascalCase/camelCase page files such as `pages/Admin.vue`) never matches, because every lookup is folded to lowercase while the key stays mixed-case.\n\nvue-router still serves the page case-insensitively, so the page renders with none of its Nuxt route-rule protections applied. The most serious consequence is an authorization bypass: an `appMiddleware` rule used as an auth gate (`routeRules: { '/Admin/dashboard': { appMiddleware: 'auth' } }`) is dropped, and `/Admin/dashboard`, `/admin/dashboard`, and `/ADMIN/dashboard` all render the protected page (and its SSR-fetched data) to an unauthenticated visitor instead of redirecting to login. The same gap drops Nuxt's other app-side route-rule behaviours for mixed-case keys, including the client redirect middleware, the app-side `ssr: false` decision, `prerender`, and payload handling.\n\n### Patches\n\nFixed in `nuxt@4.5.1` (4.x) and `nuxt@3.21.10` (3.x). The route-rule matcher now case-folds the compiled keys the same way it folds the lookup path, so key and lookup normalisation are symmetric. Both sides are gated on `router.options.sensitive`: with `sensitive: true` (case-sensitive routing) configured casing is preserved on both sides.\n\nScope note: server-emitted per-route `headers`, server `redirect`, and `proxy` are matched by Nitro's own case-sensitive route-rule matcher, not by Nuxt's app-level matcher. They are unchanged by this advisory. The fix covers the app-level protections Nuxt owns (`appMiddleware`, `appLayout`, the client redirect middleware, the app `ssr` decision, `prerender`, and payload).\n\n### Workarounds\n\nIf you cannot upgrade immediately, any one of:\n\n- Key all `routeRules` (and name your page files) in lowercase, so the keys already match the folded lookup path.\n- Set `router: { options: { sensitive: true } }` so routing and route-rule matching are both case-sensitive and exact (requests must then use the exact casing).\n- Enforce the sensitive protections server-side independently of route rules (for example a server middleware that checks auth), which does not rely on case-insensitive route-rule matching.","aliases":["CVE-2026-71315"],"modified":"2026-08-05T21:25:59.703790Z","published":"2026-08-05T21:05:18Z","database_specific":{"github_reviewed_at":"2026-08-05T21:05:18Z","nvd_published_at":null,"cwe_ids":["CWE-178","CWE-863"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/nuxt/nuxt/security/advisories/GHSA-hxvh-4h3w-prp9"},{"type":"WEB","url":"https://github.com/nuxt/nuxt/commit/619963309e082190bac4a26b05f2dd155b039b81"},{"type":"WEB","url":"https://github.com/nuxt/nuxt/commit/ad624a75ad2d215f43633f6b40be346a7194d34d"},{"type":"PACKAGE","url":"https://github.com/nuxt/nuxt"},{"type":"WEB","url":"https://github.com/nuxt/nuxt/releases/tag/v3.21.10"},{"type":"WEB","url":"https://github.com/nuxt/nuxt/releases/tag/v4.5.1"}],"affected":[{"package":{"name":"nuxt","ecosystem":"npm","purl":"pkg:npm/nuxt"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.4.7"},{"fixed":"4.5.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-hxvh-4h3w-prp9/GHSA-hxvh-4h3w-prp9.json"}},{"package":{"name":"nuxt","ecosystem":"npm","purl":"pkg:npm/nuxt"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.21.7"},{"fixed":"3.21.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-hxvh-4h3w-prp9/GHSA-hxvh-4h3w-prp9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}