Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41645

24
FAUCET Score

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's expression evaluation engine makes it possible for a malicious target server to inject and execute supported DSL expressions. This happens when HTTP response data containing helper/function syntax gets reused by multi-step templates. If the -env-vars / -ev option is explicitly enabled, this can expose host environment variables. That option is off by default, so standard configurations are not affected by the information disclosure risk. This issue has been patched in version 3.8.0.

First published: May 8, 2026Last modified: May 11, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0.0, < 3.8.0CPE matchmatch criteria
cpe:2.3:a:projectdiscovery:nuclei:*:*:*:*:*:go:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.34%
Probability of exploitation in next 30 days
EPSS Percentile
27.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0034 is in the 48th percentile among its peer group of 707 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/projectdiscovery/nuclei/v3Fixed in: 3.8.0

Vendor Advisories (1)

goGHSA-jm34-66cf-qpvrmedium

Nuclei: Environment variable disclosure via Response-Derived DSL Expressions

Apr 22, 2026

References

github.com / projectdiscovery/nuclei/commit/6c803c74d193f85f8a6d9803ce493fd302cad0eb
Patch
github.com / projectdiscovery/nuclei/commit/d2217320162d5782ca7cb95bef9dda17063818f3
Patch
github.com / projectdiscovery/nuclei/pull/7221
Issue TrackingPatch
github.com / projectdiscovery/nuclei/pull/7321
Issue TrackingPatch
github.com / projectdiscovery/nuclei/releases/tag/v3.8.0
ProductRelease Notes
github.com / projectdiscovery/nuclei/security/advisories/GHSA-jm34-66cf-qpvr
MitigationPatchVendor Advisory