Skip to content

add CVE-2026-4810#15925

Open
dwisiswant0 wants to merge 1 commit intomainfrom
dwisiswant0/add/CVE-2026-4810
Open

add CVE-2026-4810#15925
dwisiswant0 wants to merge 1 commit intomainfrom
dwisiswant0/add/CVE-2026-4810

Conversation

@dwisiswant0
Copy link
Copy Markdown
Member

PR Information

Template validation

  • Validated with a host running a vulnerable version and/or configuration (True Positive)
  • Validated with a host running a patched version and/or configuration (avoid False Positive)

Additional Details (leave it blank if not applicable)

Additional References:

@neo-by-projectdiscovery-dev
Copy link
Copy Markdown
Contributor

neo-by-projectdiscovery-dev bot commented Apr 16, 2026

Neo - Nuclei Template Review

No security issues found

Hardening Notes
  • Affected version range states '1.7.0 through 1.28.1' are vulnerable, but remediation states 'Upgrade to versions 1.28.1' which is contradictory. According to GitHub discussion CVE-2017-8917.yaml False Negative #5346 and release v1.30.0 (April 13, 2026), the actual fix is in version 1.30.0, not 1.28.1. Update description to clarify: vulnerable versions are 1.7.0 through 1.29.x, patched version is 1.30.0+.
  • Remediation section could be more specific: change 'Upgrade to versions 1.28.1 and 2.0.0a2 or later' to 'Upgrade to version 1.30.0 or later (for alpha branch: 2.0.0a3 or later)'.
  • Template validation timed out after 60 seconds - this is a nuclei tool issue, not a template security issue. The YAML structure appears syntactically correct.

Comment @pdneo help for available commands. · Open in Neo

@dwisiswant0
Copy link
Copy Markdown
Member Author

@github-actions github-actions bot requested a review from theamanrawat April 16, 2026 07:49
@dwisiswant0 dwisiswant0 force-pushed the dwisiswant0/add/CVE-2026-4810 branch from 6b8d656 to 8ea6b0c Compare April 16, 2026 07:49
Signed-off-by: Dwi Siswanto <git@dw1.io>
@dwisiswant0 dwisiswant0 force-pushed the dwisiswant0/add/CVE-2026-4810 branch from 8ea6b0c to f53866a Compare April 16, 2026 07:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants