
ProjectDiscovery / nuclei-templates
Contributions to ProjectDiscovery/nuclei-templates, the community-curated vulnerability scanning template library for the Nuclei engine.
#17355: fix(CVE-2025-12536): correct cve-id in classification
Corrected the cve-id classification metadata in the detection template for CVE-2025-12536 (SureForms <= 1.13.1 Sensitive Information Exposure).
The template contained a copy-paste mismatch where classification.cve-id was mistakenly set to CVE-2025-14437 (which corresponds to Hummingbird Performance). This duplicate identifier collision prevented proper downstream EPSS score syncing and caused CLI filtering to associate the template with the incorrect vulnerability.
Updated cve-id to the canonical identifier CVE-2025-12536, resolving the collision and ensuring accurate scoring and filtering across the repository.
#17294: fix: prevent false positive in sap-readconfigfile-disclosure
Fixed a matcher logic flaw in the detection template for sap-readconfigfile-disclosure (SAPControl SOAP ReadConfigFile).
The second HTTP verification request lacked matchers-condition: and, causing Nuclei to evaluate the matcher blocks with default OR logic. Consequently, any target returning an HTTP 200 status code triggered a false-positive configuration disclosure alert, even when ReadConfigFileResponse and <lines> were completely absent from the response body.
Added matchers-condition: and to require that the HTTP 200 status and the SOAP body indicators (ReadConfigFileResponse and <lines>) match simultaneously before flagging a vulnerability, eliminating false-positive findings in automated scans.
#17293: fix: prevent false positive in CVE-2024-33832
Fixed a matcher logic flaw in the detection template for CVE-2024-33832 (OneNav SSRF).
The template lacked a top-level matchers-condition, causing Nuclei to evaluate multiple matcher blocks with default OR logic. Consequently, any target responding with Content-Type: application/json or matching generic response indicators triggered a false-positive SSRF alert, even when no outbound interaction with the OAST server (interactsh) took place.
Added matchers-condition: and to mandate that the out-of-band interactsh protocol interaction and HTTP response indicators must match simultaneously before reporting the vulnerability, eliminating false-positive alerts in automated scans.
#17240: fix: prevent false positive in CVE-2026-31807
Fixed a matcher logic flaw in the detection template for CVE-2026-31807.
The second HTTP verification request was missing matchers-condition: and. In Nuclei, omitting this directive causes multiple matcher blocks to evaluate with OR logic. As a result, supporting indicators like an HTTP 200 status or an image/svg+xml Content-Type header caused the template to fire on benign targets even when the payload was completely sanitized and not reflected.
Added matchers-condition: and to mandate that the reflected XSS payload, the SVG MIME type, and the HTTP 200 response must all match simultaneously before reporting a vulnerability. This aligns with the related CVE-2026-31809 template and eliminates false positive alerts in automated scans.