[CVE-2025-27415] Nuxt allows DOS via cache poisoning, is Cloudflare impacted?

What is the name of the domain?

https://mysite.com/?/_payload.json

What is the issue you’re encountering

I am using Nuxt v3.15 and for the moment I can’t update to v3.16 to fix the CVE-2025-27415. Can you tell me if Cloudflare is impacted or not?

Here is the description of the vulnerability: Nuxt allows DOS via cache poisoning with payload rendering response.

If you’ve configured Cloudflare to ignore query strings, then this nuxt vulnerability would impact the resources cached at Cloudflare.

it appears this has been patched in 3.16.0 so you’d likely want to upgrade regardless of your settings in Cloudflare.

Thank you, I am fine then!

Yes, it’s just I can’t update to 3.16.0 right now but I will in the next days.

1 Like

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.