<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 16:53:24 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-310021</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-310021</link>
      <description>EUVD-2026-310021</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-310021</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41645</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41645</link>
      <description>&lt;p&gt;Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei&amp;#39;s expression evaluation engine makes it possible for a malicious target server to inject and execute supported DSL expressions. This happens when HTTP response data containing helper/function syntax gets reused by multi-step templates. If the -env-vars / -ev option is explicitly enabled, this can expose host environment variables. That option is off by default, so standard configurations are not affected by the information disclosure risk. This issue has been patched in version 3.8.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei&amp;#39;s expression evaluation engine makes it possible for a malicious target server to inject and execute supported DSL expressions. This happens when HTTP response data containing helper/function syntax gets reused by multi-step templates. If the -env-vars / -ev option is explicitly enabled, this can expose host environment variables. That option is off by default, so standard configurations are not affected by the information disclosure risk. This issue has been patched in version 3.8.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41645</guid>
    </item>
    <item>
      <title>GHSA-jm34-66cf-qpvr — Nuclei: Environment variable disclosure via Response-Derived DSL Expressions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jm34-66cf-qpvr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/projectdiscovery/nuclei/v3&lt;/p&gt;
&lt;p&gt;A vulnerability in Nuclei&amp;#39;s expression evaluation engine makes it possible for a malicious target server to inject and execute supported DSL expressions. This happens when HTTP response data containing helper/function syntax gets reused by multi-step templates. If the `-env-vars` / `-ev` option is explicitly enabled, this can expose host environment variables. That option is off by default, so standard configurations are not affected by the information disclosure risk.&lt;/p&gt;
&lt;p&gt;**Affected Component**&lt;/p&gt;
&lt;p&gt;The issue lives in `expressions.Evaluate()` at `pkg/protocols/common/expressions/` and in the unresolved-variable validation path (`hasLiteralsOnly()`).&lt;/p&gt;
&lt;p&gt;**Description**&lt;/p&gt;
&lt;p&gt;`expressions.Evaluate()` replaces placeholders first, then scans the substituted output for expressions. Because of this two-pass approach, response-derived values (including extractor output and response body content) can be reinterpreted as DSL/helper syntax on the second pass.&lt;/p&gt;
&lt;p&gt;When `-env-vars` (`-ev`) is enabled, environment variables get merged into the template variable map. A malicious target can return response data containing expressions like `{{env_var_name}}` which, when reused in a subsequent template request, resolve to actual environment variable values. This can expose sensitive host data like API keys, credentials, and tokens.&lt;/p&gt;
&lt;p&gt;Without `-ev` enabled (the default), injected DSL expressions may still trigger helper functions such as `{{md5(&amp;#34;test&amp;#34;)}}`, but this has no meaningful security impact beyond une…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/projectdiscovery/nuclei/v3&lt;/p&gt;
&lt;p&gt;A vulnerability in Nuclei&amp;#39;s expression evaluation engine makes it possible for a malicious target server to inject and execute supported DSL expressions. This happens when HTTP response data containing helper/function syntax gets reused by multi-step templates. If the `-env-vars` / `-ev` option is explicitly enabled, this can expose host environment variables. That option is off by default, so standard configurations are not affected by the information disclosure risk.&lt;/p&gt;
&lt;p&gt;**Affected Component**&lt;/p&gt;
&lt;p&gt;The issue lives in `expressions.Evaluate()` at `pkg/protocols/common/expressions/` and in the unresolved-variable validation path (`hasLiteralsOnly()`).&lt;/p&gt;
&lt;p&gt;**Description**&lt;/p&gt;
&lt;p&gt;`expressions.Evaluate()` replaces placeholders first, then scans the substituted output for expressions. Because of this two-pass approach, response-derived values (including extractor output and response body content) can be reinterpreted as DSL/helper syntax on the second pass.&lt;/p&gt;
&lt;p&gt;When `-env-vars` (`-ev`) is enabled, environment variables get merged into the template variable map. A malicious target can return response data containing expressions like `{{env_var_name}}` which, when reused in a subsequent template request, resolve to actual environment variable values. This can expose sensitive host data like API keys, credentials, and tokens.&lt;/p&gt;
&lt;p&gt;Without `-ev` enabled (the default), injected DSL expressions may still trigger helper functions such as `{{md5(&amp;#34;test&amp;#34;)}}`, but this has no meaningful security impact beyond une…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jm34-66cf-qpvr</guid>
    </item>
  </channel>
</rss>
