Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jm34-66cf-qpvr | Nuclei: Environment variable disclosure via Response-Derived DSL Expressions |
Mon, 11 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:projectdiscovery:nuclei:*:*:*:*:*:go:*:* |
Fri, 08 May 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Projectdiscovery
Projectdiscovery nuclei |
|
| Vendors & Products |
Projectdiscovery
Projectdiscovery nuclei |
Fri, 08 May 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's expression evaluation engine makes it possible for a malicious target server to inject and execute supported DSL expressions. This happens when HTTP response data containing helper/function syntax gets reused by multi-step templates. If the -env-vars / -ev option is explicitly enabled, this can expose host environment variables. That option is off by default, so standard configurations are not affected by the information disclosure risk. This issue has been patched in version 3.8.0. | |
| Title | Nuclei: Environment variable disclosure via Response-Derived DSL Expressions | |
| Weaknesses | CWE-94 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-11T18:16:02.582Z
Reserved: 2026-04-21T23:58:43.802Z
Link: CVE-2026-41645
Updated: 2026-05-11T18:15:47.931Z
Status : Analyzed
Published: 2026-05-08T04:16:18.177
Modified: 2026-05-08T19:42:49.960
Link: CVE-2026-41645
No data.
OpenCVE Enrichment
Updated: 2026-05-08T05:30:46Z
Github GHSA