blob: 25155f646b61792b476990a51e4be4303daeb7ce [file]
id: GO-2026-6571
modules:
- module: github.com/projectdiscovery/nuclei
vulnerable_at: 1.1.7
- module: github.com/projectdiscovery/nuclei/v2
vulnerable_at: 2.9.15
- module: github.com/projectdiscovery/nuclei/v3
versions:
- introduced: 3.0.0
- fixed: 3.10.0
vulnerable_at: 3.9.0
summary: |-
Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz
Mode in github.com/projectdiscovery/nuclei
cves:
- CVE-2026-76805
ghsas:
- GHSA-jpvm-9frm-hjcq
references:
- advisory: https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jpvm-9frm-hjcq
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-76805
- fix: https://github.com/projectdiscovery/nuclei/commit/ccbfb12bd01447ba25f6e755dfb2bee677736da6
- fix: https://github.com/projectdiscovery/nuclei/pull/7499
- web: https://github.com/projectdiscovery/nuclei/releases/tag/v3.10.0
source:
id: GHSA-jpvm-9frm-hjcq
created: 2026-09-28T14:08:02.503889-04:00
review_status: UNREVIEWED