↓Skip to main content

ProjectDiscovery / nuclei-templates

Contributions to ProjectDiscovery/nuclei-templates, the community-curated vulnerability scanning template library for the Nuclei engine.

#17355: fix(CVE-2025-12536): correct cve-id in classification

Corrected the cve-id classification metadata in the detection template for CVE-2025-12536 (SureForms <= 1.13.1 Sensitive Information Exposure).

The template contained a copy-paste mismatch where classification.cve-id was mistakenly set to CVE-2025-14437 (which corresponds to Hummingbird Performance). This duplicate identifier collision prevented proper downstream EPSS score syncing and caused CLI filtering to associate the template with the incorrect vulnerability.

Updated cve-id to the canonical identifier CVE-2025-12536, resolving the collision and ensuring accurate scoring and filtering across the repository.

#17294: fix: prevent false positive in sap-readconfigfile-disclosure

Fixed a matcher logic flaw in the detection template for sap-readconfigfile-disclosure (SAPControl SOAP ReadConfigFile).

The second HTTP verification request lacked matchers-condition: and, causing Nuclei to evaluate the matcher blocks with default OR logic. Consequently, any target returning an HTTP 200 status code triggered a false-positive configuration disclosure alert, even when ReadConfigFileResponse and <lines> were completely absent from the response body.

Added matchers-condition: and to require that the HTTP 200 status and the SOAP body indicators (ReadConfigFileResponse and <lines>) match simultaneously before flagging a vulnerability, eliminating false-positive findings in automated scans.

#17293: fix: prevent false positive in CVE-2024-33832

Fixed a matcher logic flaw in the detection template for CVE-2024-33832 (OneNav SSRF).

The template lacked a top-level matchers-condition, causing Nuclei to evaluate multiple matcher blocks with default OR logic. Consequently, any target responding with Content-Type: application/json or matching generic response indicators triggered a false-positive SSRF alert, even when no outbound interaction with the OAST server (interactsh) took place.

Added matchers-condition: and to mandate that the out-of-band interactsh protocol interaction and HTTP response indicators must match simultaneously before reporting the vulnerability, eliminating false-positive alerts in automated scans.

#17240: fix: prevent false positive in CVE-2026-31807

Fixed a matcher logic flaw in the detection template for CVE-2026-31807.

The second HTTP verification request was missing matchers-condition: and. In Nuclei, omitting this directive causes multiple matcher blocks to evaluate with OR logic. As a result, supporting indicators like an HTTP 200 status or an image/svg+xml Content-Type header caused the template to fire on benign targets even when the payload was completely sanitized and not reflected.

Added matchers-condition: and to mandate that the reflected XSS payload, the SVG MIME type, and the HTTP 200 response must all match simultaneously before reporting a vulnerability. This aligns with the related CVE-2026-31809 template and eliminates false positive alerts in automated scans.


View all PRs · Nuclei Templates