v3.10.0
2026-07-01T08:51:40Z•4d36300d71572853e5918b41a4367ac1536acd717af0372b373cb9afab707762
CVE-2026-41646GHSA-29rg-wmcw-hpf4bugfixdcomexpressionshttp-client-poolingimpacketjslocal-file-accessnucleiprojectdiscoveryreleasersyncscmrsecurity-fixtls-session-cachingtscmupgrade-recommendedwmi
What happened
ProjectDiscovery Nuclei release notes (v3.6.1 through v3.10.0). Notable items: v3.8.0 contains security hardening for the JS engine — respecting allow-local-file-access in require and restricting evaluation to template-authored expressions (addresses CVE-2026-41646 / GHSA-29rg-wmcw-hpf4). Other changes across releases include new features (impacket integration and new WMI/TSCH/SCMR/DCOM helper modules for JS, RSYNC module, CDP endpoint for headless mode), performance/networking improvements (per-host HTTP client pooling, TLS session caching), and multiple bug fixes (host timeout skipping, port
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- projectdiscovery_nuclei_releases
- Record identifier
- 4d36300d71572853e5918b41a4367ac1536acd717af0372b373cb9afab707762
- Enrichment time
- 2026-07-01T08:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.