Nuclei Templates v10.4.1 – Release Notes
New Templates Added: 76 | CVEs Added: 42 | First-time contributions: 10 🔥 Release Highlights 🔥 [ CVE-2026-32596 ] Glances - Information Disclosure ( @theamanrawat ) [high] 🔥 [CVE-2026-31816] Budibase - Authentication Bypass ( @theamanrawat ) [critical] 🔥 [ CVE-2026-27483 ] MindsDB - Remote Code Execution ( @thewhiteh4t ) [high] 🔥 [CVE-2026-24477] AnythingLLM - Information Disclosure ( @dhiyaneshdk ) [high] 🔥 [ CVE-2026-22739 ] Spring Cloud Config Server - Path Traversal (@0x_Akoko, @vulnh0lic) [high] 🔥 [ CVE-2026-21445 ] Langflow - Broken Access Control ( @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-3055 ] Citrix NetScaler SAML IDP - Memory Overread ( @watchtowr , @shaikhyaser , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-1581 ] wpForo Forum <= 2.4.14 - SQL Injection ( @Shivam Kamboj) [critical] (kev) (vKEV) 🔥 [ CVE-2025-71260 ] BMC FootPrints - Deserialization of Untrusted Data (RCE) ( @watchtowr , @dhiyaneshdk ) [critical] 🔥 [ CVE-2025-68043 ] LottieFiles WordPress Plugin <= 3.0.0 - Missing Authorization ( @pussycat0x ) [high] 🔥 [ CVE-2025-32463 ] Sudo - Local Privilege Escalation via chroot ( @SeungAh-Hong ) [critical] (kev) (vKEV) 🔥 [ CVE-2025-14437 ] WordPress Hummingbird <= 3.18.0 - Sensitive Information Exposure via Log File ( @pussycat0x ) [high] 🔥 [ CVE-2025-6984 ] langchain-ai langchain - XML External Entity Injection ( @nukunga ) [high] 🔥 [ CVE-2025-5947 ] Service Finder Bookings - Authentication Bypass ( @sedat4ras ) [critical] (kev) (vKEV) 🔥 [ CVE-2024-43144 ] Cost Calculator Builder <= 3.2.15 - SQL Injection ( @Shivam Kamboj) [critical] 🔥 [ CVE-2023-34092 ] Vite Dev Server - Information Exposure ( @ritikchaddha ) [high] 🔥 What's Changed Bug Fixes Fixed invalid hostname generation affecting template execution (PR #15641 , Issue #15624 ). Fixed extractor DSL by adding a missing condition (PR #15729 ). Moved CVE-2026-23829 from http to the correct network folder (PR #15738 , Issue #15633 ). Fixed reference URLs in CVE-2025-66516 (PR #15646 ). False Negatives Improved detection in FTP Service - Credential Weakness template, reducing underreporting (PR #15726 , Issue #15681 ). Addressed false negative in CVE-2024-3273 detection (Issue #15654 ). Addressed false negative in CVE-2021-25032 detection (Issue #13647 ). False Positives Reduced false positives and improved accuracy in the following templates: CVE-2025-71243 — excluded pages that echo back user input (PR #15665 ). CVE-2025-66516 — tightened matcher logic (PR #15581 ). CVE-2023-5652 (PR #15622 ). CVE-2023-7337 (PR #15620 ). CVE-2022-21587 — added matchers-condition: and (PR #15621 ). CVE-2009-1872 ColdFusion fingerprint (PR #15601 ). CVE-2002-1131 SquirrelMail fingerprint (PR #15595 ). CVE-2021-35042 (Issue #15241 ). flexnet-operations-panel — reduced high false positive rate (PR #15600 ). mercurial-hgignore — added text/xml and <?xml to negative matchers (PR #15623 ). aws-bucket-takeover — excluded S3 account regional namespace buckets (PR #15608 ). hubspot-takeover — switched to header-based detection for NotFoundResolver (PR #15583 ). Enhancements Enriched classification metadata and renamed CVE-2020-15718 (PR #15677 ). Updated classification metadata for CVE-2024-55550 (PR #15666 ). Updated classification metadata for CVE-2024-13726 (PR #15648 ). Updated apache-activemq-artemis-detect.yaml detection logic (PR #15717 ). Applied AI-assisted tagging improvements across multiple templates (PR #15571 ). Templates Added [CVE-2026-33868] Mastodon - Open Redirect ( @theamanrawat ) [medium] 🔥 [ CVE-2026-32596 ] Glances - Information Disclosure ( @theamanrawat ) [high] 🔥 [ CVE-2026-32583 ] Webnus Inc. Modern Events Calendar - Broken Access Control ( @theamanrawat ) [medium] 🔥 [CVE-2026-31816] Budibase - Authentication Bypass ( @theamanrawat ) [critical] 🔥 [ CVE-2026-30928 ] Glances - Information Disclosure ( @theamanrawat ) [high] 🔥 [CVE-2026-28288] Dify User Enumeration via Observable Response Discrepancy ( @dhiyaneshdk ) [medium] 🔥 [ CVE-2026-27483