v3.10.0

2026-07-01T08:51:40Z4d36300d71572853e5918b41a4367ac1536acd717af0372b373cb9afab707762
CVE-2026-41646GHSA-29rg-wmcw-hpf4bugfixdcomexpressionshttp-client-poolingimpacketjslocal-file-accessnucleiprojectdiscoveryreleasersyncscmrsecurity-fixtls-session-cachingtscmupgrade-recommendedwmi

What happened

ProjectDiscovery Nuclei release notes (v3.6.1 through v3.10.0). Notable items: v3.8.0 contains security hardening for the JS engine — respecting allow-local-file-access in require and restricting evaluation to template-authored expressions (addresses CVE-2026-41646 / GHSA-29rg-wmcw-hpf4). Other changes across releases include new features (impacket integration and new WMI/TSCH/SCMR/DCOM helper modules for JS, RSYNC module, CDP endpoint for headless mode), performance/networking improvements (per-host HTTP client pooling, TLS session caching), and multiple bug fixes (host timeout skipping, port

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
projectdiscovery_nuclei_releases
Record identifier
4d36300d71572853e5918b41a4367ac1536acd717af0372b373cb9afab707762
Enrichment time
2026-07-01T08:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.