Improper Input Validation in Nuclei by ProjectDiscovery
CVE-2026-76805
5.3MEDIUM
What is CVE-2026-76805?
The vulnerability in Nuclei, versions 3.0.0 to 3.9.0, lies in the improper evaluation of substituted runtime data multiple times, enabling sensitive information leakage. When configured with environment variable expansion, a malicious target can manipulate data returned during scans, allowing the potential disclosure of sensitive environment variables like credentials and API keys. This issue particularly affects multi-step DAST or fuzz templates, where response data may be reused through an internal extractor. The vulnerability has been adequately addressed in version 3.10.0.
Affected Version(s)
nuclei >= 3.0.0, < 3.10.0