github.com/projectdiscovery/nuclei/v3
Go10 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/projectdiscovery/nuclei/v3page 1 of 1
- CVE-2024-27920HIGHCVSS 7.4EG 7.4fixed in 3.2.02024-03-15
projectdiscovery/nuclei is a fast and customisable vulnerability scanner based on simple YAML based DSL. A significant security oversight was identified in Nuclei v3, involving the execution of unsigned code templates through workflows. Th…
- CVE-2024-40641HIGHCVSS 7.4EG 7.4fixed in 3.3.02024-07-17
Nuclei is a fast and customizable vulnerability scanner based on simple YAML based DSL. In affected versions it a way to execute code template without -code option and signature has been discovered. Some web applications inherit from Nucl…
- CVE-2024-43405HIGHCVSS 7.4EG 7.4fixed in 3.3.22024-09-04
Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2, a vulnerability in Nuclei's template signature verification system could allow an attacker to bypass the signature che…
- CVE-2026-41282MEDIUMCVSS 4.0EG 4.0fixed in 3.8.02026-04-20
ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).
- CVE-2026-41645MEDIUMCVSS 5.3EG 5.3fixed in 3.8.02026-05-08
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's expression evaluation engine makes it possible for a malicious target server to inject and execute …
- CVE-2026-41646MEDIUMCVSS 5.5EG 5.5fixed in 3.8.02026-05-08
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's JavaScript protocol runtime allows JavaScript templates to read local .js and .json files through t…
- CVE-2026-76802MEDIUMCVSS 4.7EG 4.7fixed in 3.10.02026-09-22
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned code-template signature check before accepting a template that contains both a fuzzin…
- CVE-2026-76803MEDIUMCVSS 5.3EG 5.3fixed in 3.10.02026-09-22
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not enforce the local-file sandbox when a JavaScript template supplies the allowAllFiles MySQL DSN option…
- CVE-2026-76804MEDIUMCVSS 5.5EG 5.5fixed in 3.10.02026-09-22
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enforce the -file capability gate when resolving file: protocol templates referenced by a workflow. An…
- CVE-2026-76805MEDIUMCVSS 5.3EG 5.3fixed in 3.10.02026-09-22
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime data more than once, creating a second evaluation pass that allow…
Check whether github.com/projectdiscovery/nuclei/v3 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/projectdiscovery/nuclei/v3 CVEs against the assets you own.
Book a Demo →