Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the Goja JavaScript runtime embedded in the javascript: protocol under pkg/js/ contains an out-of-bounds heap write that can corrupt memory during template evaluation and allow native code execution on the scanner host. A malicious untrusted JavaScript template can trigger the flaw during a normal scan, including from a template init section that runs during initialization. JavaScript templates execute without the -code flag and unsigned JavaScript templates run by default on affected versions, exposing CLI and SDK deployments that accept third-party templates. This issue is fixed in version 3.10.0.
This CVE has been withdrawn by MITRE
MITRE marked CVE-2026-76819 as REJECTED on . It is no longer considered a valid vulnerability record. The original content below is preserved for historical reference only.
Further research determined the issue results from a dependency.
CVE-2026-76819
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 8.6
- EchelonGraph score
- Not yet assessedThis CVE record was withdrawn by its numbering authority, so there is no vulnerability to rate.
- EG Score
- —
- EG Risk
- —
- EPSS PROB
- —
- EPSS %ILE
- —
- KEV
- Not listed
Published
September 22, 2026
Last Modified
September 22, 2026
Advisory Details (5)
Auto-updated Sep 22, 2026v3.10.0
Patch available: projectdiscovery/nuclei v3.10.0
https://github.com/projectdiscovery/nuclei/releases/tag/v3.10.0commit 1fe6025b966c (projectdiscovery/nuclei)
Fix landed in projectdiscovery/nuclei commit 1fe6025b966c — awaiting tagged release
https://github.com/projectdiscovery/nuclei/commit/1fe6025b966cbb95ed4d9f40abfb629b6cbd27b2feat(templates): require signatures for javascript templates
Fix merged in projectdiscovery/nuclei PR #7514 on 2026-07-03 — awaiting tagged release
https://github.com/projectdiscovery/nuclei/pull/7514bump goja
Fix merged in projectdiscovery/nuclei PR #7467 on 2026-06-20 — awaiting tagged release
https://github.com/projectdiscovery/nuclei/pull/7467Arbitrary Code Execution via Goja JavaScript Engine Vulnerability · Advisory · projectdiscovery/nuclei · GitHub
https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-vxg7-f2jj-jmqmVendor Advisories for CVE-2026-76819(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Weakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 3× in last 7d / 3× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-09-23 04:31 UTCEG score recompute▼ 8.60
- 2026-09-22 16:51 UTCEG score recompute
- 2026-09-22 16:49 UTCMITRE cvelistV5first tracked
Related CVEs(same CWE)
Same CWE
10 shownCWE-787 · CWE-94
Frequently asked(4)
What is CVE-2026-76819?
When was CVE-2026-76819 disclosed?
What is the CVSS score of CVE-2026-76819?
How do I remediate CVE-2026-76819?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-76819
Is Your Infrastructure Affected by CVE-2026-76819?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.