{"api_version":"v1","generated_at":"2026-10-08T02:00:00+00:00","product":{"cve_count":11,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-projectdiscovery-nuclei-c7d23d0624cf","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/nuclei","name":"nuclei","next_cursor":null,"observations":[{"affected":"nuclei: >= 3.0.0, < 3.10.0","affected_versions_present":true,"cve_id":"CVE-2026-76805","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-76805","fixed":"3.10.0.","last_modified":"2026-09-22T18:19:16.720Z","patch_url":"https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jpvm-9frm-hjcq","primary_source":"","published":"2026-09-22T16:48:49.791Z"},{"affected":"nuclei: >= 3.0.0, < 3.10.0","affected_versions_present":true,"cve_id":"CVE-2026-76802","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-76802","fixed":"3.10.0.","last_modified":"2026-09-22T17:04:53.745Z","patch_url":"https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jpf4-98qj-qr67","primary_source":"","published":"2026-09-22T16:47:00.360Z"},{"affected":"nuclei: >= 3.0.0, < 3.10.0","affected_versions_present":true,"cve_id":"CVE-2026-76804","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-76804","fixed":"3.10.0.","last_modified":"2026-09-28T19:17:51.204Z","patch_url":"https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-qgw5-7j4f-fg97","primary_source":"","published":"2026-09-22T16:41:46.188Z"},{"affected":"nuclei: >= 3.0.0, < 3.10.0","affected_versions_present":true,"cve_id":"CVE-2026-76803","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-76803","fixed":"3.10.0.","last_modified":"2026-09-25T23:44:38.902Z","patch_url":"https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-xhmx-w2j4-rw3q","primary_source":"","published":"2026-09-22T16:27:59.627Z"},{"affected":"nuclei: 3.7.0 < 3.11.1","affected_versions_present":true,"cve_id":"CVE-2026-92718","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-92718","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-24T14:22:52.529Z","patch_url":"","primary_source":"","published":"2026-09-16T17:31:38.380Z"},{"affected":">= 3.0.0, < 3.8.0","affected_versions_present":true,"cve_id":"CVE-2026-41645","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41645","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-11T18:16:02.582Z","patch_url":"https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jm34-66cf-qpvr","primary_source":"","published":"2026-05-08T03:17:19.302Z"},{"affected":">= 3.0.0, < 3.8.0","affected_versions_present":true,"cve_id":"CVE-2026-41646","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41646","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-08T14:11:15.673Z","patch_url":"https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-29rg-wmcw-hpf4","primary_source":"","published":"2026-05-08T03:14:49.908Z"},{"affected":"3.0.0 < 3.8.0","affected_versions_present":true,"cve_id":"CVE-2026-41282","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41282","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-21T00:59:19.998Z","patch_url":"https://github.com/projectdiscovery/nuclei/commit/d2217320162d5782ca7cb95bef9dda17063818f3","primary_source":"","published":"2026-04-20T07:10:30.246Z"},{"affected":">= 3.0.0, < 3.3.2","affected_versions_present":true,"cve_id":"CVE-2024-43405","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-43405","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-04T16:21:54.357Z","patch_url":"https://github.com/projectdiscovery/nuclei/commit/0da993afe6d41b4b1b814e8fad23a2acba13c60a","primary_source":"","published":"2024-09-04T15:36:23.277Z"},{"affected":">= 3.0.0, < 3.3.0","affected_versions_present":true,"cve_id":"CVE-2024-40641","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-40641","fixed":"3.3.0.","last_modified":"2024-08-13T20:55:48.064Z","patch_url":"https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-c3q9-c27p-cw9h","primary_source":"","published":"2024-07-17T17:34:10.792Z"},{"affected":">= 3.0.0, < 3.2.0","affected_versions_present":true,"cve_id":"CVE-2024-27920","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-27920","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-02T00:41:55.794Z","patch_url":"","primary_source":"","published":"2024-03-15T19:25:00.748Z"},{"affected":"< 2.9.9","affected_versions_present":true,"cve_id":"CVE-2023-37896","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-37896","fixed":"2.9.9.","last_modified":"2024-10-08T18:13:54.292Z","patch_url":"https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-2xx4-jj5v-6mff","primary_source":"","published":"2023-08-04T15:34:11.804Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"projectdiscovery"}}
