v3.11.0
2026-07-06T08:51:41Z•3154aa3a1b0ecbf49aff3797e5a3fd933b75d1328cb6d361c59158b8b9d7f5ac
CVE-2026-41646GHSA-29rg-wmcw-hpf4code-executionjavascript-protocolnucleinuclei-templatessecurity-hardeningsupply-chaintemplate-sandboxtemplate-signing
What happened
ProjectDiscovery Nuclei releases (v3.6.2→v3.11.0) introduce multiple security hardenings and fixes. Most notable: v3.11.0 enforces digital signatures for templates using the javascript: protocol — unsigned JS templates are now skipped (breaking change; custom/private JS templates must be signed before use; official nuclei-templates are pre-signed). This follows earlier sandbox/network/code-template protections and reduces JS runtime attack surface introduced by recent additions (v3.9 added Go-backed JS helper modules such as wmi/scmr/dcom). v3.8.0 fixed a security issue (CVE-2026-41646 / GHSA-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- projectdiscovery_nuclei_releases
- Record identifier
- 3154aa3a1b0ecbf49aff3797e5a3fd933b75d1328cb6d361c59158b8b9d7f5ac
- Enrichment time
- 2026-07-06T08:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.