projectdiscovery/nuclei
59.7
Adequate · 6 August 2026
82k
lines of production code
Go
primary language
3
measurements over time
What this system is
This system is a modular vulnerability scanner and security assessment platform that executes templates across diverse protocols including HTTP, DNS, SSL, and headless browsers. It features a comprehensive JavaScript runtime for complex template logic and supports remote execution via WMI, DCOM, and Task Scheduler. The architecture includes a robust template management system with signing, caching, and multi-source loading, alongside extensive fuzzing and input parsing capabilities.
How it got here
2020–2023 — Nuclei v3 SDK and engine rewrite
111 changes.
This period was defined by the comprehensive rewrite of the Nuclei engine to support a modular, multi-protocol execution framework and a public Go SDK. The work introduced a new template execution model with workflow support, expanded protocol coverage including SSL, WHOIS, and file operations, and integrated advanced JavaScript capabilities for template logic.
2024–2026 — JavaScript bindings and fuzzing engine
53 changes.
This period focused on expanding the JavaScript runtime with extensive libraries for Active Directory attacks, remote execution, and network protocols, alongside the introduction of a modular fuzzing engine. The team also standardized input handling and authentication strategies to support diverse data sources and security testing workflows.
Features
AI-generated templates and parallel template loading
Users can now generate Nuclei templates from natural language prompts via the new \ai\_loader.go\ module, which calls an external API to create and save templates. The template loader has been refactored to support parallel, concurrent template loading for improved startup performance, and includes a new \path\_filter.go\ for path-based inclusion and exclusion of templates.
pkg/catalog/loader · high confidence
Add AWS S3 template catalog support and improve template path handling
Users can now store and retrieve templates from an AWS S3 bucket via the new \pkg/catalog/aws\ package, which provides a \Catalog\ for downloading and resolving template paths. Additionally, the \IsTemplate\ and \IsCustomTemplate\ functions have been updated to properly handle absolute paths containing excluded directories (like \.git\ or \helpers\) and to correctly identify custom templates, preventing false positives or negatives in template filtering and indexing.
pkg/catalog/config · high confidence
Add DCE/RPC library for Active Directory enumeration and remote command execution
A new \dcerpc\ JavaScript library is introduced, exposing a DCE/RPC client backed by the \goimpacket\ library. This enables Active Directory attack templates to perform enumeration via EPMAPPER, SAMR, LSARPC, SVCCTL, TSCH, WINREG, and SRVSVC, as well as remote command execution via WMI (WmiExec) and SMB (SmbExec). The library provides methods such as \EnumServices\, \EnumSessions\, \EnumProcesses\, \EnumLoggedOnUsers\, and \WmiExec\, mapping to existing nmap SMB scripts. All network traffic is routed through Nuclei's fastdialer and is subject to the per-execution network policy.
pkg/js/libs/dcerpc · high confidence
Add Elasticsearch and Splunk HEC reporting exporters
Users can now export Nuclei results to Elasticsearch or Splunk HEC. The new Elasticsearch exporter sends JSON payloads to an ES index, supporting host/IP, port, SSL, and basic auth. The new Splunk HEC exporter sends JSON payloads to a Splunk HEC endpoint, supporting host, port, SSL, SSL verification, and a HEC token. Both exporters use a random user-agent header and validate required configuration options.
pkg/reporting/exporters/es · high confidence
Add GitHub issue tracker integration
A new GitHub issue tracker integration has been added to the reporting system. This allows users to automatically create and manage GitHub issues for detected vulnerabilities. The integration supports configuration options such as base URL, username, owner, project name, and issue labels. It also includes filtering capabilities via allow and deny lists, and can check for duplicate issues to avoid creating redundant tickets.
pkg/reporting/trackers/gitea, pkg/reporting/trackers/github, pkg/reporting/trackers/linear · high confidence
Add GoExec adapter for Windows helper modules
The \pkg/js/libs/goexec\ package introduces a Go-based adapter that bridges JavaScript helper calls to the FalconOps \goexec\ library. This enables the \wmi\, \tsch\, \scmr\, and \dcom\ helper modules to execute Windows operations via Go. The adapter includes a \Request\ struct to pass parameters, an \Auth\ struct to handle various Windows authentication methods (password, NT hash, Kerberos, etc.), and an \ExecutionOptions\ struct to configure execution behavior. The \GoExecRunner\ maps these requests to the appropriate upstream library calls, handling output collection, error redaction, and network policy enforcement. Tests verify that credentials are properly redacted from results and that network policies are correctly enforced before making calls.
pkg/js/libs/goexec · high confidence
Add JavaScript LDAP library for Active Directory enumeration
The \pkg/js/libs/ldap\ package introduces a new JavaScript API for interacting with LDAP servers, enabling Active Directory enumeration directly from Nuclei templates. The \ldap.Client\ constructor supports \ldap://\, \ldaps://\, \ldapi://\, and \cldap://\ schemes, with network policy enforcement to restrict access to local network endpoints. The library provides methods to authenticate (\Authenticate\), search for AD objects (\FindADObjects\), and retrieve specific user and group sets (e.g., \GetADUsers\, \GetADGroups\, \GetADActiveUsers\). It also includes utility functions for joining and negating LDAP filters, and handles timestamp decoding for AD attributes.
pkg/js/libs/ldap · high confidence
Add JavaScript bindings for file system operations
Users can now access file system utilities from JavaScript templates. The new \nuclei/fs\ module exposes \ListDir\ to list files or directories, \ReadFile\ and \ReadFileAsString\ to read file contents, and \ReadFilesFromDir\ to read all files in a directory, all with path normalization for security.
pkg/js/libs/fs · high confidence
Add Kerberos client library for JavaScript bindings
Introduced a new Go package for Kerberos functionality, exposing a JavaScript API via the \nuclei/kerberos\ module. This includes a \Client\ constructor that accepts a domain and optional controller, with support for configuring IP address and timeout. The implementation adds \EnumerateUser\ to retrieve AS-REP hashes and \SendToKDC\ to handle TCP/UDP communication with Key Distribution Centers, enforcing network policy checks on controller addresses.
pkg/js/libs/kerberos · high confidence
Add Markdown reporting exporter with path-traversal protection
A new Markdown reporting exporter has been added to the product, allowing users to export scan results as Markdown files. The implementation includes a filename sanitization function that explicitly blocks path traversal sequences (such as '../' and '\\') to ensure that generated files remain within the configured report directory, addressing a potential security vulnerability where hostile host or template IDs could escape the output directory.
pkg/reporting/exporters/markdown · high confidence
Add MongoDB export destination for reporting
A new MongoDB exporter has been added to the reporting pipeline, allowing users to export scan results directly to a MongoDB database. The exporter supports configuration via a connection string (which can be set using the MONGO\_CONNECTION\_STRING environment variable), a target collection name, and batch size for memory management. Results are buffered in memory and flushed to the database in batches or upon closure, with an option to omit raw request/response data to reduce file size.
pkg/reporting/exporters/mongo · high confidence
Add MySQL service fingerprinting and connection capabilities
The JavaScript API now includes a \mysql\ module providing \IsMySQL\, \FingerprintMySQL\, \Connect\, and \ConnectWithDSN\ methods. \IsMySQL\ and \FingerprintMySQL\ perform a native handshake parse to detect MySQL services and extract details like version, capabilities, and authentication plugins. \Connect\ and \ConnectWithDSN\ establish authenticated connections using a custom dialer that respects network policies. The implementation includes memoization to avoid redundant network calls and adds a \sandboxDSN\ function that enforces local file access restrictions by stripping the \allowAllFiles\ option unless explicitly permitted.
pkg/js/libs/mysql · high confidence
Add Oracle database interaction library for JavaScript bindings
Introduces a new \nuclei/oracle\ JavaScript library that allows scripts to detect Oracle database instances and establish connections. The library includes memoization for detection calls to improve performance, enforces network policy restrictions via a custom dialer, and implements security hardening by normalizing or rejecting trace file DSN options unless local file access is explicitly allowed.
pkg/js/libs/oracle · high confidence
Add PDF export for scan results
Users can now export scan results as a formatted PDF report. The new PDF exporter collects result events, optionally omits raw request/response data, and generates a styled document with a summary of findings by severity. A corresponding test suite validates the exporter's behavior, including concurrency safety and file generation.
pkg/reporting/exporters/pdf · high confidence
Add RDP detection and analysis functions to the JS library
The \pkg/js/libs/rdp\ package now exposes three new functions for interacting with Remote Desktop Protocol (RDP) services: \IsRDP\ to detect if a host is running an RDP server, \CheckRDPAuth\ to verify authentication status and retrieve metadata, and \CheckRDPEncryption\ to identify supported security layers and encryption levels. These functions are memoized to cache results per execution context, improving performance for repeated calls.
pkg/js/libs/rdp · high confidence
Add Rsync library for JS bindings
Added the Rsync library to the JS bindings, providing functions to check if a host is running an Rsync server and to list modules or files within a module. The implementation includes memoization for the IsRsync check and uses the go-rsync library for communication.
pkg/js/libs/rsync · high confidence
Add SARIF export format for vulnerability reports
A new SARIF (Static Analysis Results Interchange Format) exporter has been added to the reporting pipeline. This allows users to export scan results in a standardized format compatible with GitHub Security and other static analysis tools. The exporter maps Nuclei severity levels to SARIF levels and includes metadata for GitHub Security pages.
pkg/reporting/exporters/sarif · high confidence
Add SSL/TLS protocol support with cipher and version enumeration
Users can now perform SSL/TLS scans using the new SSL protocol handler. This adds support for specifying minimum and maximum TLS versions, selecting scan modes (ctls, ztls, openssl, or auto), and enumerating supported TLS versions and cipher suites. The implementation includes a test verifying the addition of duration fields to the resulting events, ensuring that timing information is captured during SSL/TLS interactions.
pkg/protocols/ssl · high confidence
Add Telnet library with connection, info, and memoized detection functions
Users can now use the new telnet library to detect if a host is running a Telnet server, retrieve server information (including encryption support and banner), and establish authenticated Telnet connections. The library exposes an IsTelnet function for detection, a TelnetClient with Connect and Info methods for deeper interaction, and memoizes the detection logic to avoid redundant network calls.
pkg/js/libs/telnet · medium confidence
Add TypeScript code generator for JavaScript bindings
Introduced a new Go-based tool (tsgen) that parses Go source files to automatically generate TypeScript definition files (.ts). This tool processes modules containing WMI, TSC, SCM, and DCOM helpers, producing type definitions that enable static typing and improved developer experience when using the associated JavaScript bindings.
pkg/js/devtools/tsgen/cmd · high confidence
Add UserAgent configuration type for headless HTTP requests
Users can now configure the UserAgent for headless HTTP requests via a new \UserAgent\ type that supports options like \random\, \off\, \default\, and \custom\. This type includes custom JSON and YAML unmarshalling to parse string values into the appropriate enum, and provides a JSON schema definition for the configuration.
pkg/model/types/userAgent · high confidence
Add VNC library with connection and detection capabilities
The VNC library now exposes JavaScript bindings for interacting with VNC servers. Users can use \vnc.IsVNC()\ to detect if a host is running a VNC server and retrieve its banner, or use \vnc.VNCClient().Connect()\ to establish a connection and authenticate with a password. The implementation includes memoization for detection calls and enforces network policies via the execution context.
pkg/js/libs/vnc · high confidence
Add WHOIS protocol support with duration tracking
Users can now perform WHOIS queries using the new WHOIS protocol implementation. The feature includes support for querying domain and IP addresses via the RDAP protocol, with results exposed in the output event. A \duration\ field is now included in the output, recording the time taken for the WHOIS request in seconds, allowing templates to match or extract based on response time.
pkg/protocols/whois · high confidence
Add YAML and JSON serialization for severity types
The severity model now supports serialization and deserialization for both YAML and JSON formats. The \Severity\ type and its \Holder\ wrapper implement \MarshalYAML\, \UnmarshalYAML\, \MarshalJSON\, and \UnmarshalJSON\ methods, allowing users to configure severity filters in configuration files and API payloads. A corresponding test suite verifies that severity values are correctly parsed from and marshaled to string representations.
pkg/model/types/severity · high confidence
Add advanced concurrency and header injection example
The examples/advanced directory now includes a new Go example demonstrating how to run Nuclei scans with concurrent execution using a sized waitgroup, inject custom HTTP headers via the SDK, and enable passive scanning mode. This showcases advanced SDK usage including template filtering by protocol type and tags.
examples/advanced · high confidence
Add disk-backed deduplication for Nuclei scan results
A new deduplication layer for Nuclei-generated issues has been added to the reporting pipeline. The implementation persists a hash of each scan result to a LevelDB store on disk, allowing the system to track and filter duplicate findings across sessions. This enables long-term storage of scan data, which can be used for further analysis or reporting. The change includes both the core deduplication logic and the associated unit tests.
pkg/reporting/dedupe · high confidence
Add file protocol support for local and remote SMB paths
The file protocol now handles remote SMB targets in addition to local files. Users can specify UNC paths (e.g., \\\fs01ackup ile.txt\) or \smb://\ URLs as template inputs. Authentication is supported via template fields (\smb-user\, \smb-password\, \smb-domain\, \smb-hash\) or embedded in the URL. The implementation includes path parsing, directory enumeration, and file reading over SMB, along with tests for path resolution and credential handling.
pkg/protocols/file · high confidence
Add memogen tool for transparent memoization
A new CLI tool named 'memogen' has been added to the codebase. This tool scans Go source files for the '@memo' annotation and automatically generates memoized versions of the annotated functions. It uses a template to wrap the original function logic in a caching layer, allowing for transparent memoization of arbitrary function signatures.
cmd/memogen · high confidence
Add response highlighting for ASCII and hex dump outputs
The response highlighter helper now supports highlighting matches in both standard ASCII responses and hex dump representations. For ASCII content, matched substrings are colored using ANSI escape codes. For binary/hex dump content, the system parses the hex and ASCII sections of a hex dump, highlighting the corresponding bytes and characters. This allows users to visually identify matched patterns in binary responses, with the highlighting applied to both the hexadecimal values and the ASCII representation within the dump output.
pkg/protocols/common/helpers/responsehighlighter · high confidence
Add scan-charts CLI tool for generating scan event visualizations
A new command-line utility, cmd/scan-charts, has been added to the Nuclei project. This tool allows users to generate HTML reports from scan event data. It supports scanning a directory of events, starting a local server to view them, or generating a static HTML output file. The tool is part of the 'stats' build and utilizes the charts package for data processing.
cmd/scan-charts · high confidence
Add simple Go example for Nuclei v3
A new Go example (examples/simple/simple.go) demonstrates how to initialize and run the Nuclei v3 library, including configuration for template filters, optional metrics server, and target loading.
examples/simple · high confidence
Add speed control example demonstrating dynamic concurrency and rate-limiting
An example is added at examples/with\_speed\_control/main.go that demonstrates how to initialize the Nuclei engine with specific concurrency and rate-limiting settings, and then dynamically adjust the global rate limit, template threads, bulk size, and payload concurrency during execution to control the speed of scanning operations.
_examples/with\_speed\control · high confidence
Add support for parsing Burp XML input files
Users can now provide Burp Suite XML files as input for scanning. The new \burp\ format handler parses the XML, decodes the base64-encoded raw requests, and converts them into the standard \RawRequest\ type, enabling existing fuzzing and input-type features to process Burp data directly.
pkg/input/formats/burp · high confidence
Added CIDR and ASN expansion utilities
A new \expand\ package has been introduced in \pkg/utils/expand\ to provide helper functions for expanding network ranges. The \CIDR\ function converts a CIDR notation string into a list of individual IP addresses, while the \ASN\ function expands an Autonomous System Number into its constituent CIDRs and then into individual IPs, leveraging the \projectdiscovery/mapcidr\ library.
pkg/utils/expand · high confidence
Added DNS resolution and network port helper functions to the DSL
A new DSL module was introduced in pkg/operators/common/dsl, implementing two new helper functions for template expressions: 'resolve', which performs DNS lookups for various record types (A, AAAA, CNAME, NS, TXT, SRV, PTR, MX, SOA, CAA), and 'getNetworkPort', which returns a default port if the provided port is in a known list. The implementation relies on the 'projectdiscovery/dsl' and 'projectdiscovery/govaluate' libraries, and includes corresponding unit tests to verify the DNS resolution logic.
pkg/operators/common · high confidence
Added JSON utility for parsing GraphQL responses
A new \jsonutil\ package was introduced to handle decoding JSON into GraphQL query data structures. This utility provides a custom JSON decoder that supports GraphQL-specific features like fragments and embedded structs, enabling the application to correctly parse complex GraphQL API responses.
pkg/reporting/trackers/linear/jsonutil · high confidence
Added JSONL input format for parsing HTTP requests
A new JSONL input format has been introduced to parse HTTP requests from JSON files. This allows users to provide input data in a structured JSON Lines format, where each line represents a request with URL, header, body, and raw request details. The implementation includes a parser that decodes each line into a request object and processes it, enabling seamless integration with existing input handling workflows.
pkg/input/formats/json · high confidence
Added Java deserialization payload generation helpers and scan strategy types
The \deserialization\ package now includes helper functions to generate Java deserialization payloads for various gadgets (including jdk7u21, jdk8u20, commons-collections, and groovy1) and supports multiple output encodings (raw, hex, gzip, base64). Additionally, the \templates/extensions\ package defines file extension constants for JSON, YAML, and YML, while the \scanstrategy\ package introduces a new \ScanStrategy\ type with \Auto\, \HostSpray\, and \TemplateSpray\ options to control scanning behavior.
pkg/protocols/common/helpers/deserialization, pkg/templates/extensions, pkg/types/scanstrategy · high confidence
Added JavaScript libraries for Active Directory credential extraction and secrets dumping
Added two new JavaScript libraries for Active Directory attacks: \pkg/js/libs/krbroast\ and \pkg/js/libs/secretsdump\. The \krbroast\ library exposes functions for AS-REP roasting and Kerberoasting, allowing templates to extract password hashes from the KDC. The \secretsdump\ library exposes a \Client\ class that performs DCSync (via DRSUAPI) to replicate directory secrets, including NT/LM hashes and password history for a specified user. Both libraries integrate with the existing Nuclei JS runtime and enforce network allowlist policies.
pkg/js/libs/krbroast, pkg/js/libs/secretsdump · high confidence
Added MSSQL and POP3 JS libraries for service detection and interaction
Added new JavaScript libraries for MSSQL and POP3 protocols. The MSSQL library provides functions to connect to a database, execute queries, and perform fingerprinting via TDS pre-login probes. The POP3 library allows checking if a host is running a POP3 server. Both libraries include memoization for performance and are implemented in the \pkg/js/libs/mssql\ and \pkg/js/libs/pop3\ directories.
pkg/js/libs/mssql · high confidence
Added NucleiJS utility package for JavaScript bindings and SQL helpers
A new 'nucleijs' package was introduced in pkg/js/utils, providing a Go wrapper around the goja JavaScript runtime to manage VM lifecycles, error handling, and context propagation for JS libraries. The package also includes utility functions for extracting structured data from SQL rows. This change adds new capabilities rather than modifying existing behavior.
pkg/js/utils · high confidence
Added OpenAPI 3.0 specification parsing and request generation
Users can now provide OpenAPI 3.0 specification files (YAML/JSON) as input for scanning. The tool automatically downloads remote OpenAPI specs, validates them, and generates corresponding HTTP requests for each defined endpoint, including support for global and operation-specific security schemes.
pkg/input/formats/openapi · high confidence
Added Redis library with memoized functions and Lua script support
Added a new Redis library (pkg/js/libs/redis) that exposes functions for connecting to Redis servers, retrieving server information, checking authentication status, and running Lua scripts. The implementation includes a memoized wrapper for repeated calls to improve performance, and enforces network policy restrictions via the protocol state.
pkg/js/libs/redis · high confidence
Added Telnet login and NTLM info parsing capabilities
The telnetmini package now supports basic Telnet authentication and NTLM information gathering. Users can detect encryption support via Telnet negotiation packets and parse NTLM challenge responses to extract system information such as NetBIOS/DNS names, product versions, and timestamps. The implementation includes a fix to prevent slice-bounds panics on truncated NTLM challenges by enforcing a minimum 48-byte header length, ensuring robust parsing of server responses.
pkg/utils/telnetmini · high confidence
Added automatic scan service for technology-based template execution
A new automatic scan service has been introduced in the Nuclei engine, enabling automatic technology detection and template execution. The service leverages Wappalyzer to identify technologies and maps the results to template tags, allowing for dynamic, technology-specific scanning. The implementation includes a new \automaticscan\ package with core service logic, utility functions for template loading and clustering, and corresponding unit tests.
pkg/protocols/common/automaticscan · high confidence
Added bindgen tool for generating Goja bindings and documentation
A new 'bindgen' tool has been introduced in the \pkg/js/devtools/bindgen\ directory to automatically generate Goja bindings for native Go packages. This tool parses Go source code and produces three types of output: Go bindings (\.go\ files), JavaScript representation files (\.js\ files), and Markdown documentation (\.md\ files). The tool requires \js-beautify\ and \gofmt\ to be installed in the system PATH. This addition supports the broader Nuclei v3 JavaScript engine updates by providing a standardized way to expose native Go libraries to the JS runtime.
pkg/js/devtools/bindgen · high confidence
Added frequency tracker to reduce redundant fuzzing requests
A new frequency tracker has been introduced in the fuzzing module to identify and skip parameters that are frequently occurring but yield few results. This mechanism reduces the number of requests made during fuzzing for parameters that are less likely to produce significant outcomes, thereby optimizing the fuzzing process.
pkg/fuzz/frequency · high confidence
Added gRPC client library for JavaScript templates
A new \nuclei/grpc\ JavaScript library is now available, allowing templates to connect to gRPC endpoints. The library wraps the \grpcurl\ SDK and exposes a \Client\ with methods to invoke unary RPCs, list services and methods, and describe symbols. It supports both server reflection and precompiled protoset descriptors, and routes all connections through the existing network and local-file-access policies.
pkg/js/libs/grpc · high confidence
Added goroutine hang detection and stack trace dumping
A new monitoring utility has been introduced to detect stuck scanner processes by tracking goroutine counts. When a hang is detected, the system automatically writes a stack trace to a dump file and triggers registered callbacks, allowing for easier investigation of hangs.
pkg/utils/monitor · high confidence
Added markdown formatting utilities for report generation
The markdown reporting exporter now includes a new utility package containing functions to generate bold text, links, horizontal lines, and tables in Markdown format. Additionally, code blocks are now properly escaped to prevent markdown syntax from breaking the output, ensuring that special characters like backticks and backslashes are safely handled within code blocks.
pkg/reporting/exporters/markdown/util · high confidence
Added offline HTTP protocol support for processing raw HTTP responses from files
Users can now use the new offline HTTP protocol to process raw HTTP responses stored in .txt files. The implementation includes parsing file and directory inputs, handling glob patterns, and converting raw HTTP responses into a structured map for template execution. This enables template authors to write rules that match against offline HTTP response data, supporting matchers and extractors on headers, body, and status codes.
pkg/protocols/offlinehttp · high confidence
Added random IP generation and template placeholder replacement utilities
New utility packages have been introduced to support protocol operations. The randomip package provides a function to generate a random IP address within one or more specified CIDR ranges, supporting both IPv4 and IPv6. The replacer package introduces functions to perform on-the-fly template variable substitution, supporting both standard and single-key replacement with various marker styles. Both packages include comprehensive test coverage.
pkg/protocols/common/randomip · high confidence
Added scan event charting and HTTP server for visualizing Nuclei scan data
A new \pkg/scan/charts\ package has been introduced to provide HTTP endpoints and HTML rendering for visualizing Nuclei scan events. This includes a live server that exposes routes for concurrency, fuzzing, slow templates, and request-per-second metrics, alongside the ability to generate static HTML reports of these charts using the \go-echarts\ library.
pkg/scan/charts · high confidence
Added scan statistics tracking via build tags
A new 'stats' build tag enables the \pkg/scan/events\ package to record scan metadata and events as JSONL files. This adds the \ScanStatsWorker\ implementation and supporting types (\ScanEvent\, \ScanConfig\) that write configuration and event data to disk, while the default (non-stats) build provides no-op functions.
pkg/scan/events · high confidence
Added scrapefuncs tool to generate JS helper function documentation
A new Go-based tool named 'scrapefuncs' has been added to the project. This tool scans the codebase for JavaScript helper functions and generates corresponding JSDoc comments and Markdown documentation. This aids in maintaining up-to-date reference materials for the JavaScript runtime and protocol-specific helpers.
pkg/js/devtools/scrapefuncs · high confidence
Added stats storage mechanism for engine statistics
A new stats package has been introduced to provide a storage mechanism for tracking and displaying vital statistics of the engine at various durations. This includes functions to create entries, increment counters, and display or force-display warnings for specific metrics, supporting the engine's observability features.
pkg/utils/stats · high confidence
Added template metadata caching and filtering
A new persistent metadata cache has been introduced in the catalog index to store lightweight template information (ID, path, modification time, authors, tags, severity, protocol type, and validation status) for faster lookups. The system now supports filtering templates by author, tag, ID (with wildcard support), severity, and protocol type, with explicit inclusion and exclusion logic (e.g., IncludeTags can override specific ExcludeTags). The cache is thread-safe, persists to disk, and validates metadata freshness via file modification times.
pkg/catalog/index · high confidence
Added time-based delay analyzer for fuzzing
A new time-delay analyzer has been introduced to the fuzzing engine, implementing a linear regression-based approach inspired by ZAP to detect time-based vulnerabilities. The analyzer measures response times against varying sleep delays to identify predictable timing dependencies, with corresponding unit tests validating the detection algorithm across various scenarios.
pkg/fuzz/analyzers/time · high confidence
Added tsgen tool for generating TypeScript definitions from Go modules
Added a new devtool named tsgen that parses Go modules written in Goja and generates corresponding TypeScript definition (.d.ts) files. This tool provides intellisense support for editors like VSCode and serves as documentation for the node modules. The implementation includes AST utilities for type conversion, a parser to extract entities and methods from Go code, and a scraper to handle external types, effectively bridging Go exports to TypeScript interfaces and classes.
pkg/js/devtools/tsgen · high confidence
Added uncover integration for target discovery
Introduced the 'uncover' package in pkg/protocols/common/uncover, providing functions to retrieve targets from external intelligence sources. The new code includes GetTargetsFromUncover for direct queries and GetUncoverTargetsFromMetadata to execute multiple engine-specific queries (e.g., Shodan, Censys) defined in template metadata, outputting results as a stream of strings.
pkg/protocols/common/uncover · high confidence
CLI runner refactored with profiling, leak testing, and benchmarking support
The Nuclei CLI entry point (cmd/nuclei/main.go) was refactored to support CPU, memory, and trace profiling, and to enable goroutine leak detection via new test suites. A benchmark test suite was added to measure enumeration performance, and a leak test ensures no unexpected goroutine leaks remain after a scan. Additionally, a YAML configuration file (issue-tracker-config.yaml) was introduced to define settings for issue trackers (GitHub, GitLab, Gitea, Jira, Linear, MongoDB, and Elasticsearch), providing a structured way to configure tracker-specific options like authentication, project names, and filtering.
cmd/nuclei · high confidence
Centralized initialization of protocol client pools
A new \protocolinit\ package has been introduced to serve as a central entry point for initializing various protocol client pools. This includes DNS, HTTP signing, network, and RDAP client pools, as well as the JS compiler. The \Init\ function in this new file coordinates the setup of these components, ensuring they are properly configured before use.
pkg/protocols/common/protocolinit · high confidence
Custom PostgreSQL driver for network control
A new \pgwrap\ package introduces a custom PostgreSQL database driver that wraps the standard \lib/pq\ driver. This allows the application to intercept database connections and route them through a controlled network dialer, enabling better management of database connections within the execution context.
pkg/js/utils/pgwrap · high confidence
Expanded JavaScript bindings for network, database, and security protocols
The JavaScript runtime now exposes a significantly broader set of protocol-specific modules, enabling direct interaction with a wide range of services and security mechanisms from scripts. New bindings include HTTP, gRPC, and raw network connections; database clients for MySQL, MSSQL, and Oracle; and specialized security libraries for Kerberos, LDAP, and RDP. Additional modules provide access to SMTP, SSH, Telnet, Redis, POP3, and file system operations, alongside utility libraries for byte manipulation, string/struct packing, and console output.
pkg/js/generated/go · high confidence
HTTP input provider now supports multiple input formats
The HTTP input provider has been updated to support multiple input formats, including Burp, JSON, YAML, OpenAPI, and Swagger. This allows users to load inputs from various file types directly, expanding the range of data sources that can be used for HTTP-based inputs.
pkg/input/provider/http · high confidence
Honeypot detection to reduce scan noise
A new honeypot detector has been added to the protocol scanning pipeline. It tracks distinct template matches per normalized host and flags hosts that exceed a configurable threshold, allowing the scanner to identify and potentially suppress responses from honeypots, thereby reducing scan noise.
pkg/protocols/common/honeypotdetector · high confidence
Initial Helm chart for Nuclei and Interactsh
Adds a new Helm chart that deploys the Nuclei scanner and the Interactsh service to Kubernetes. The chart includes templates for the Nuclei CronJob, the Interactsh Deployment, Service, and Ingress, along with the necessary ConfigMaps, ServiceAccount, and helper templates to manage the release.
helm · high confidence
Interactsh client implementation and configuration
The interactsh client is now fully implemented in the common protocols package, introducing a new client structure with configurable caching, polling, and cooldown durations. This includes the addition of options for fuzzing parameter tracking, stop-at-first-match behavior, and debug logging, alongside the definition of default configuration values and error constants.
pkg/protocols/common/interactsh · high confidence
Introduce GoJS module and function registration system
Added new GoJS integration files (gojs.go, set.go) that provide a module system for the Goja JavaScript runtime. This includes a GojaModule struct for managing JavaScript modules and a RegisterFuncWithSignature function that registers Go functions with the Goja runtime, supporting context injection and execution ID propagation.
pkg/js/gojs · high confidence
Introduce JavaScript-based flow execution engine for templates
Added a new flow execution engine in \pkg/tmplexec/flow\ that allows templates to use JavaScript (ECMAScript 5.1) for conditional execution and request orchestration. This enables features such as iterating over slices, executing requests conditionally (e.g., \flow: dns() && http()\), and managing template context variables. The implementation includes a \FlowExecutor\ that compiles and runs JavaScript code, with built-in helpers like \iterate\ and \Dedupe\ to facilitate template logic.
pkg/tmplexec/flow · high confidence
Introduce Krbforge library for Kerberos ticket forging
Added the Krbforge library to the JavaScript runtime, enabling Nuclei templates to forge Kerberos golden and silver tickets using provided NT hashes or AES keys. The library includes a security restriction that prevents writing ticket cache (ccache) files outside the execution sandbox by default, requiring the -allow-local-file-access flag to write to arbitrary paths.
pkg/js/libs/krbforge · high confidence
Introduce StringSlice type for flexible string array handling
A new \StringSlice\ type has been added to \pkg/model/types/stringslice\, providing a flexible way to handle both single strings and arrays of strings in model definitions. This type supports unmarshalling from both JSON and YAML, automatically converting single string values into a slice, and normalizes values by lowercasing and trimming whitespace. A \RawStringSlice\ variant is also introduced, which preserves the original casing of string values. This change allows models to accept either a single string or a list of strings for fields that require multiple values.
pkg/model/types/stringslice · high confidence
Introduce TemplateMan CLI (tmc) for template management
A new command-line utility, tmc, is introduced to standardize and manage Nuclei templates via the TemplateMan API. The tool provides subcommands to lint, validate, format, and enhance templates, as well as automatically update max-request counters. It supports processing single files or directories, handles user-home directory paths, and logs errors to a specified file.
cmd/tmc · high confidence
Introduce automated documentation and checksum generation tools
Added new command-line tools to automate the generation of Markdown documentation and JSON schemas for the template system, and to compute SHA1 checksums for template files. The docgen tool now produces both MD and JSON schema outputs, while the generate-checksum tool walks the templates directory to produce a checksum file, improving consistency and reducing manual maintenance.
cmd/docgen · high confidence
Introduce cluster ID to template ID mapping and protocol type definitions
Added new types in the templates package to support mapping cluster IDs to template IDs and defining supported protocol types. The \cluster\_mappings.go\ file introduces a \ClusterMappingsMap\ struct with methods to retrieve, copy, and access mappings of cluster IDs to template IDs. The \types.go\ file defines the \ProtocolType\ enum and related helper types (\TypeHolder\, \ProtocolTypes\) that handle serialization (JSON/YAML) and validation for protocol types such as DNS, HTTP, SSL, and others, enabling the system to recognize and process various network protocols.
pkg/templates/types · high confidence
Introduce extensible analyzer framework for fuzzing
The fuzzing module now includes a new \analyzers\ package that provides a pluggable interface for analyzing fuzzing results. This introduces a registration system for analyzers, allowing different analysis strategies to be added and selected by name. The package also includes utility functions for applying payload transformations, such as replacing placeholders with random numbers or strings, which can be used by analyzers during the fuzzing process.
pkg/fuzz/analyzers · high confidence
Introduce file-based and multi-source authentication providers
Users can now configure authentication using a secrets file, which supports both static and dynamic (lazy-fetched) secrets. The new FileAuthProvider parses these files to map domains and regex patterns to auth strategies. Additionally, a MultiAuthProvider allows combining multiple auth sources, with the system returning the first matching strategy found across all configured providers.
pkg/authprovider · high confidence
Introduce generic template execution engine
Added a new generic execution engine in the tmplexec package that processes template requests sequentially without intermediate logic. The implementation supports context cancellation for graceful shutdown, tracks execution results using atomic booleans, and integrates with host error caching to mark failures or remove entries based on protocol type.
pkg/tmplexec/generic · high confidence
Introduce global matchers for template-level result filtering
Added a new global matchers system that allows templates to define matchers which are applied across all requests, enabling template-level filtering of results. The implementation includes a new \globalmatchers\ package with a \Storage\ struct to hold and manage global matcher items, and integrates this into the \ExecutorOptions\ via a \GlobalMatchers\ field. This change enables templates to specify matchers that are evaluated against every request's output, providing a way to filter or process results at a higher level than individual protocol requests.
pkg/protocols · high confidence
Introduce high-performance JSON utility package
A new \pkg/utils/json\ package has been added to provide fast JSON encoding and decoding. On supported platforms (Linux, Darwin, or Windows on amd64/arm64 with Go 1.20–1.26), it uses the \sonic\ library, while all other systems fall back to \go-json\. The package exposes standard marshaling, unmarshaling, and encoder/decoder functions, along with \Marshaler\ and \Unmarshaler\ interfaces and a \Message\ type for raw JSON handling.
pkg/utils/json · high confidence
Introduce modular reporting client with issue tracker and exporter support
The reporting module has been refactored into a new modular client architecture that supports multiple issue trackers (GitHub, GitLab, Gitea, Jira, Linear) and exporters (Markdown, SARIF, JSON, JSONL, PDF, Elasticsearch, Splunk, MongoDB). Users can now configure and route scan results to various external systems and file formats through a unified reporting interface, enabling more flexible integration with external tools and issue tracking workflows.
pkg/reporting · high confidence
Introduce multi-protocol template execution engine
Added a new \multiproto\ template execution engine that allows templates to define multiple protocols in a single template. The engine executes each protocol in the defined order, passing extracted dynamic values from one protocol to the next via a shared template context. This enables complex, multi-step scanning workflows where the output of one protocol (e.g., HTTP) can be used as input for another (e.g., SSL or DNS) within the same template.
pkg/tmplexec/multiproto · high confidence
Introduce new fuzzing engine for dynamic HTTP request mutation
Added a new fuzzing engine in the \pkg/fuzz\ package that enables dynamic fuzzing of HTTP requests. This includes a \Rule\ struct that defines how to mutate request parts (query, header, path, body, cookie, or the entire request) using various modes (single, multiple) and rule types (replace, prefix, postfix, infix, replace-regex). The implementation features variable evaluation with interactsh URL support, frequency-based parameter deduplication to avoid redundant requests, and a statistics tracking system for monitoring fuzzing progress and results.
pkg/fuzz · high confidence
Introduce structured data format encoding and decoding for fuzzing
Added a new dataformat package that provides a unified interface for encoding and decoding various data formats (JSON, XML, Raw, Form, and Multipart Form) used in fuzzing. This enables the fuzzing engine to automatically detect, parse, and serialize request payloads in these formats, supporting features like handling duplicate form fields and preserving metadata for multipart uploads.
pkg/fuzz/dataformat · high confidence
Introduce template metadata and classification model structures
Added new model definitions for template metadata (Info) and vulnerability classification (Classification) in the pkg/model package. The Info struct captures template-level details such as name, author, tags, description, impact, references, severity, and arbitrary metadata, while the Classification struct holds CVE, CWE, CVSS, EPSS, and CPE identifiers. These structures support JSON and YAML marshalling and include schema extensions for documentation and validation.
pkg/model · high confidence
Introduce template signing and verification for Nuclei templates
Added a new template signing subsystem in the signer package, enabling users to sign and verify Nuclei templates. The implementation includes a KeyHandler for managing ECDSA key pairs (generation, parsing, and storage) and a TemplateSigner that produces and validates digital signatures. The system supports signing templates that contain code protocols or JavaScript, and enforces security by preventing the re-signing of executable templates. Tests confirm that signatures are correctly applied and verified, including handling of CRLF line endings and template imports.
pkg/templates/signer · high confidence
Introduced Catalog interface for template and file management
Added a new Catalog interface in the catalog package that defines methods for opening files, resolving template paths, and retrieving template lists. This provides a standardized way to access and manage template and payload files within the application.
pkg/catalog · high confidence
Introduced Operators struct and Result handling for template execution
Added the Operators struct, which encapsulates matchers, extractors, and their conditions, along with a Result struct to store match and extraction outcomes. This includes the MakeDynamicValuesCallback function to iterate over dynamic template values, enabling the template engine to process and combine results from multiple matchers and extractors during template execution.
pkg/operators · high confidence
Introduced contextargs package to manage shared template context and port resolution
Added the \contextargs\ package to provide a shared context structure for workflows, including a \MetaInput\ type for target metadata and a \UseNetworkPort\ method that intelligently resolves network ports. This method preserves explicitly specified ports (e.g., \host:80\) while replacing scheme-implied ports (e.g., \http://host\) with template defaults, addressing issue \#7323. The package also includes a \portutil\ utility for resolving service names to ports and a \render\ package for template text rendering with Interactsh marker support.
pkg/protocols/common/contextargs · high confidence
Introduced event creation helpers for protocol responses and operator results
Added new functions in the eventcreator package to wrap output events with operator results and handle debug variable dumping. Specifically, CreateEvent and CreateEventWithAdditionalOptions process compiled operators against output events, appending results and managing dynamic values, while CreateEventWithOperatorResults provides a simpler wrapper for direct operator results. This enables the system to properly format and return structured events containing both extracted values and dynamic data for protocol responses.
pkg/protocols/common/helpers/eventcreator · high confidence
Introduces HTTP request/response caching via project file storage
The pkg/projectfile package now provides a new ProjectFile type that caches HTTP interactions (requests and responses) in a hybrid map store. This allows the application to store and retrieve HTTP records, effectively enabling a local cache for network traffic. The implementation includes utility functions for hashing and marshalling/unmarshalling HTTP data, and integrates with the existing hybrid storage mechanism.
pkg/projectfile · high confidence
Introduces a new error kind for template logic issues
A new error kind, ErrTemplateLogic, has been added to the nucleierr package to categorize errors arising from template logic, such as missing variables or timeouts. This allows the system to distinguish these expected template-related errors from other types of failures.
pkg/types/nucleierr · high confidence
Introduces a new template loading and caching architecture
The template loading and compilation logic has been restructured into new, dedicated files (parser.go, compile.go, cache.go, etc.) within the templates package. This change introduces a robust caching mechanism for parsed and compiled templates, enabling performance improvements by avoiding redundant parsing and compilation. The refactoring also introduces a capability system that gates template execution based on specific flags (e.g., \-headless\, \-code\, \-dast\), ensuring that templates requiring specific capabilities are only loaded when those capabilities are explicitly enabled.
pkg/templates · high confidence
Introduces internal infrastructure for cloud upload, concurrency control, and fuzz testing
Adds internal packages to support new capabilities: \internal/pdcp\ handles chunked upload of scan results to the ProjectDiscovery Cloud (PDCP) dashboard; \internal/httpapi\ exposes an HTTP endpoint to dynamically adjust concurrency settings (threads, rate limits, etc.) at runtime; \internal/colorizer\ maps template severity levels to specific terminal colors; \internal/fuzzplayground\ provides a mock HTTP server with SQL injection and other vulnerabilities for testing fuzzing templates; and \internal/runner\ gains helpers for directory paths, health checks, and lazy authentication template loading.
internal · high confidence
Introduction of the tmplexec package for template execution
The tmplexec package has been introduced to handle the execution of templates, replacing the previous common/executer package. This new structure separates template execution logic from individual protocol logic, supporting three distinct execution engines: Generic for single-protocol requests, MultiProtocol for parallel multi-protocol execution, and Flow for JavaScript-defined workflow templates. The implementation includes a central TemplateExecuter that routes execution to the appropriate engine based on the template configuration, while also integrating scan event tracking and improved error handling for template compilation and execution.
pkg/tmplexec · high confidence
Jira reporting tracker implementation with advanced template support
The Jira reporting tracker has been implemented in the codebase, introducing a new integration for creating and managing Jira issues. The implementation supports advanced template-based custom fields using Go's text/template syntax (e.g., \{{.Name}}\), allowing users to dynamically construct issue titles and descriptions based on vulnerability data. It also retains support for legacy \$variable\ syntax for backward compatibility. The change includes helper functions for formatting markdown, tables, and links specifically for Jira's markup language, as well as filtering capabilities based on severity levels.
pkg/reporting/trackers/jira · high confidence
New CLI tools for template signing and fuzzing playground
Two new command-line tools are introduced in the cmd/tools directory. The 'signer' utility allows users to sign and verify Nuclei templates using a certificate and private key, ensuring template integrity. Additionally, a 'fuzzplayground' tool is added to run a local server for fuzzing testing, providing a dedicated environment for fuzzing workflows.
cmd/tools · high confidence
New DNS protocol implementation with clustering and DNSSEC support
The DNS protocol handler has been rewritten to support clustering for improved performance, allowing requests to be grouped and deduplicated based on template and resolver configuration. The implementation adds support for DNSSEC record types (NSEC, NSEC3, DNSKEY, RRSIG) and enables recursion by default. Additionally, the engine now supports context cancellation to allow graceful shutdown of DNS requests.
pkg/protocols/dns · high confidence
New HTTP utility functions for URL and header handling
Added new utility functions in the HTTP utilities package to improve request handling. The \UpdateURLPortFromPayload\ function allows dynamic port updates in URLs based on payload data, while \SetHeader\ ensures headers are only set if not already present, preventing user-supplied values from being overwritten. Additionally, \HasTrailingSlash\ detects trailing slashes in paths containing default variables. These utilities support more flexible and robust HTTP request construction.
pkg/protocols/utils/http · high confidence
New JSONL reporting exporter with batched output and raw data omission
A new JSONL (JSON Lines) reporting exporter has been added to the tool, allowing users to export scan results in a line-delimited JSON format. The exporter supports an 'omit-raw' option to exclude raw request and response data from the output, and features a configurable batch size to flush results to the output file in batches rather than writing every single event immediately. This provides a more memory-efficient and performant way to generate JSONL reports compared to the previous single-file JSON exporter.
pkg/reporting/exporters/jsonl · high confidence
New JavaScript HTTP client for Nuclei templates
Added a new \nuclei/http\ module for JavaScript templates, exposing an HTTP client with configurable timeout, redirect, and body-size limits, plus cookie support and header injection. The client reuses the scan's fastdialer for connection management. Additionally, the module provides \DecodeNTLM\ to parse NTLM Type-2 challenge headers and \NegotiateNTLM\ to generate NTLM negotiate messages, enabling NTLM authentication flows in templates.
pkg/js/libs/http · high confidence
New JavaScript SMB client and net library
Added a new \nuclei/smb\ module exposing a JavaScript API for SMB operations, including \SMBClient\ methods for protocol discovery (\ConnectSMBInfoMode\, \ListSMBv2Metadata\), share enumeration (\ListShares\, \ListDir\, \ListTree\), file reading (\ReadFile\), and vulnerability detection (\DetectSMBGhost\). The implementation includes memoization of these functions to cache results based on execution context and parameters. Additionally, a new \nuclei/net\ library was introduced, providing JavaScript bindings for TCP/UDP connections (\Open\, \OpenTLS\) with timeout and data sending capabilities (\Send\, \SendHex\, \SendArray\, \RecvFull\).
pkg/js/libs/smb · high confidence
New JavaScript bindings for network, database, and protocol clients
Added TypeScript definitions and JavaScript bindings for a wide range of protocols and services, enabling scriptable interactions directly from Nuclei templates. The update introduces clients for HTTP, gRPC, and raw network (TCP/UDP) communication, as well as database connectors for MySQL, MSSQL, and Oracle. It also adds specialized clients for Kerberos (including AS-REP and Kerberoast operations), LDAP, DCE/RPC (SMB, RPC dump, SAMR, services enumeration), and utility modules for byte manipulation, file system access, and console logging.
pkg/js/generated/ts · high confidence
New JavaScript global helpers and utilities
Added new JavaScript global functions for base64 encoding and decoding (btoa, atob), JSON serialization (to\_json, dump\_json), array conversion (to\_array), and hex-to-ASCII conversion (hex\_to\_ascii). Additionally, the global scope now includes Active Directory helper functions (getDomainControllerName) and network utilities such as isPortOpen, isUDPPortOpen, and getNetworkPort, alongside improved random number generation using crypto/rand.
pkg/js/global · high confidence
New JavaScript libraries for byte manipulation, console logging, and IKEv2 protocol support
Added three new JavaScript libraries to the Nuclei engine: a \bytes\ module providing a \Buffer\ class for handling byte arrays with methods like \Write\, \WriteString\, \Bytes\, \String\, \Len\, \Hex\, \Hexdump\, and \Pack\; a \goconsole\ module that maps JavaScript console calls (log, warn, error) to the Go \gologger\ logger; and an \ikev2\ module exposing \IKEMessage\, \IKENonce\, and \IKENotification\ types to construct and encode IKEv2 protocol messages in JavaScript.
pkg/js/libs/bytes · high confidence
New Postgres library for JavaScript bindings
Added a new Postgres library for JavaScript bindings, exposing a PGClient with methods to check for Postgres services, connect, and execute queries. The implementation includes memoization of internal functions to cache results based on execution ID, host, port, and credentials. The code also introduces a connection URL builder that escapes credentials and sanitizes database names to prevent query injection, as verified by new tests.
pkg/js/libs/postgres · high confidence
New SMB exploit script and Go structs library
Added a new JavaScript exploit script for the SMBv3.1.1 vulnerability ([CVE redacted]) in \pkg/js/libs/structs/smbexploit.js\, which constructs and sends a malicious SMB negotiation packet to test for the vulnerability. Simultaneously, a new Go library \pkg/js/libs/structs/structs.go\ was introduced to provide \Pack\, \Unpack\, and \CalcSize\ functions for serializing and deserializing binary data, enabling the JS script to construct the required byte structures.
pkg/js/libs/structs · high confidence
New SMTP library for JavaScript templates
Added a new \nuclei/smtp\ module for JavaScript templates, enabling scripts to interact with SMTP services. This includes an \SMTPMessage\ struct to construct email headers and body, and a \Client\ class that provides methods to detect SMTP services (\IsSMTP\), check for open relays (\IsOpenRelay\), and send emails (\SendMail\).
pkg/js/libs/smtp · high confidence
New SSH client library for JavaScript templates
Users can now use the SSH client in JavaScript templates to connect to SSH servers, retrieve server information, and execute remote commands. The new \ssh\ library exposes an \SSHClient\ with methods for connecting via password or private key, gathering handshake information, running commands, and managing the connection lifecycle.
pkg/js/libs/ssh · high confidence
New WAF detection and stats tracking for scan results
The stats module now tracks and reports on HTTP status codes, error kinds, and Web Application Firewall (WAF) detections. A new WAF detector uses embedded regex patterns to identify various WAFs (such as Cloudflare, ModSecurity, and Wordfence) in HTTP responses. The stats tracker collects these metrics and provides a summary of the top status codes, errors, and WAF detections in the CLI output.
pkg/output/stats · high confidence
New WMI, Task Scheduler, SCMR, and DCOM helper modules for remote execution
Added new JavaScript helper modules for Windows remote execution: WMI (with \command\, \proc\, and \call\ methods), Task Scheduler (\create\ and \demand\), SCMR (service control manager with \create\), and DCOM (with \mmc\ execution). Each module exposes an \Auth\ constructor and a \Client\ object that allows scripts to execute commands, manage services, schedule tasks, or invoke DCOM methods on remote targets. A test was added for the WMI module to verify request mapping.
(repo-wide) · high confidence
New XSS reflection context analyzer for fuzzing
The fuzzing engine now includes a new XSS context analyzer that evaluates the HTML response to determine where a reflected payload appears. It distinguishes between contexts such as HTML body text, generic attributes, URL attributes (like href or src), event handler attributes (like onclick), and executable script contexts. This allows the fuzzer to tailor payloads based on the specific reflection location, improving the detection of reflected XSS vulnerabilities.
pkg/fuzz/analyzers/xss · high confidence
New code protocol for executing custom scripts
A new code protocol has been introduced, allowing users to execute custom scripts (e.g., shell, Python) within the Nuclei engine. The implementation includes a \Request\ struct with fields for specifying the engine, source code, and sandboxing options. It supports capturing standard output and standard error, and enforces execution policies such as requiring templates to be signed and verified. The protocol also registers helper functions in the JS runtime to detect the host OS and architecture, enabling conditional logic in templates.
pkg/protocols/code · high confidence
New core engine execution and workflow handling
The \pkg/core\ package introduces a new \Engine\ struct that manages template and workflow execution. The engine now supports executing templates via \TemplateSpray\ and \HostSpray\ scan strategies, handling concurrency through a configurable \WorkPool\ that separates headless and default task pools. Workflow execution is implemented with recursive subtemplate support, allowing parent templates to pass context and extracted values to child templates. The engine also includes logic for clustering templates to reduce request counts and handles self-contained templates in parallel.
pkg/core · high confidence
New filepath utility for safe path containment checks
A new \filepathutil\ package was added to provide safe filepath operations, specifically for sandboxing file access in template environments. It introduces functions to check if a path is contained within a directory, with proper canonicalization to handle symlinks and platform-specific path differences (such as case sensitivity on Windows). The package also includes a function to detect hard-linked regular files, with platform-specific implementations for Unix and Windows.
pkg/utils/filepath · high confidence
New hmap-backed input provider for list-type inputs
The \pkg/input/provider/list\ package now implements a hybrid hmap/filekv backed input provider for handling list-type inputs (such as URLs, files, stdin, and uncover sources). This new \ListInputProvider\ supports streaming or storing results using different key-value stores, handles CIDR and ASN-based input expansion, and manages deduplication and exclusion counts. The implementation includes test cases for CIDR expansion and IP resolution, along with test data files for ASN inputs.
pkg/input/provider/list · high confidence
New input format support for OpenAPI, Postman, Swagger, Burp, and Proxify
The tool now accepts multiple request source formats as inputs for fuzzing. Users can provide OpenAPI 3.0, Swagger 2.0, Postman Collection, Burp Suite XML, and Proxify JSONL files. The module parses these formats to generate HTTP requests, supporting features like server URL iteration, parameter handling (query, header, path, cookie), and request body generation for various content types (JSON, XML, form-data, etc.). Additionally, the system supports variable templating via ytt for YAML inputs and allows skipping format validation for debugging.
pkg/input/formats · high confidence
New modular fuzzing component architecture
The fuzzing engine has been refactored into a modular component system that isolates request parts (body, headers, cookies, path, and query parameters) into separate, reusable components. Each component handles its own parsing, iteration, and rebuilding logic, which improves code maintainability and allows for more precise mutation of individual request elements. This change introduces a new \component\ package with dedicated files for each part of the HTTP request, enabling more granular control over fuzzing operations.
pkg/fuzz/component · high confidence
New network protocol implementation with support for service names, multiple ports, and duration tracking
The network protocol handler has been refactored into a new, comprehensive implementation that supports multiple ports, IANA service names (e.g., ftp, ssh), and TLS connections. Users can now specify ports using standard service names or comma-separated lists, with automatic deduplication and open-port verification. The update also introduces \stop-at-first-match\ functionality for network templates, tracks operation duration in results, and improves variable handling by pre-compiling template variables and DSL functions. Additionally, the network client pool now supports custom dialers for proxy and SSL template configurations.
pkg/protocols/network · high confidence
New payload generation and map utility infrastructure
The \pkg/protocols/common/generators\ package introduces a new payload generation system, including \PayloadGenerator\ and \Iterator\ implementations for Battering Ram, Pitchfork, and Cluster Bomb attack types. It adds map utility functions (\MergeMaps\, \CopyMap\, \MergeMapsInto\) and environment variable handling (\EnvVars\). The change also includes YAML/JSON schema support for attack types and validation logic for payload loading.
pkg/protocols/common/generators · high confidence
New progress tracking and statistics display mechanism
The \pkg/progress\ package has been introduced to handle progress display and runtime statistics. It provides a \StatsTicker\ implementation that tracks and displays metrics such as templates, hosts, requests, matched items, and errors. The component supports both standard and JSON output formats, configures a metrics server, and includes tests to verify that periodic stats are only requested when the interval is positive.
pkg/progress · high confidence
New raw HTTP request parsing and fuzzing infrastructure
The \pkg/protocols/http/raw\ package now provides a dedicated, standalone implementation for parsing raw HTTP requests, separating this logic from the broader HTTP protocol handler. This includes a new \Parse\ and \ParseRawRequest\ functions that handle path automerging, unsafe mode processing, and self-contained request construction. Additionally, a comprehensive fuzzing harness (\fuzz.go\, \fuzz\_harness.go\) and associated test corpus have been added to exercise raw HTTP parsing across safe, unsafe, and path-automerge modes. The \pkg/protocols/http/signer\ package introduces a new AWS v4 signing capability, allowing HTTP requests to be signed using AWS credentials, with support for both static and default configuration-based credential retrieval.
pkg/protocols/http/raw · high confidence
New template installer with safe extraction and update logic
The installer package now provides a complete template management system. It handles fresh installation, updates, and cleanup of orphaned templates, while ensuring safe extraction of template archives by rejecting zip-slip path traversal attempts. A cross-process file lock prevents race conditions during concurrent updates, and the system now regenerates template metadata (index and checksums) after cleanup to maintain consistency.
pkg/installer · high confidence
New type definitions and utility functions for scan configuration and resume state
The \pkg/types\ package now includes \types.go\, \interfaces.go\, and \resume.go\. The \types.go\ file introduces the \Options\ struct, which defines the comprehensive set of configuration options for the Nuclei scanner, including flags for templates, protocols, proxies, headless browser settings, and concurrency limits. The \interfaces.go\ file provides utility functions for type conversion, such as \ToString\, \ToStringSlice\, and \ToByteSlice\, which handle the conversion of various data types to strings or byte slices. The \resume.go\ file introduces the \ResumeCfg\ and \ResumeInfo\ structures to manage scan progression and state, allowing the scanner to resume interrupted scans. These changes provide the foundational types and utilities for managing scan options and state.
pkg/types · high confidence
New utility functions for URL parsing, variable generation, and TLS configuration
The \pkg/protocols/utils\ package now includes new utilities to support protocol operations. \fields.go\ adds functions to extract and return structured metadata (host, port, IP, scheme, URL) for JSON output, handling edge cases like IPv6 and default ports. \variables.go\ introduces functions to generate known variables (BaseURL, Host, Port, etc.) from URLs and DNS names, supporting HTTP, DNS, and WebSocket protocols. \utils.go\ provides helper functions for cleaning JSON tags, configuring TLS client certificates, calculating content length, and formatting HTTP headers. Tests are added for all new functionality.
pkg/protocols/utils · high confidence
New utility helpers for HTTP probing, template paths, and ordered maps
The \pkg/utils\ package now includes several new utilities: an HTTP probing helper (\http\_probe.go\) that normalizes IPv6 literals and determines scheme order based on port heuristics; a \CaptureWriter\ for testing log output; a \TransformIndex\ function for safe array indexing; an \InsertionOrderedStringMap\ that preserves key order during YAML/JSON unmarshalling; a \TemplatePathURL\ function that resolves template paths and URLs; and general helpers like \ReaderFromPathOrURL\ and \GetRateLimiter\. Tests are added for each new component.
pkg/utils · high confidence
New workflow execution framework with conditional subtemplate support
Users can now define workflows that execute multiple templates in sequence, with the ability to conditionally run subtemplates based on the results of previous steps. The new \pkg/workflows\ package introduces a \Workflow\ structure that chains templates, allowing users to specify templates or directories to run, filter them by tags, and define matchers that evaluate template results using AND/OR conditions to trigger subsequent subtemplates.
pkg/workflows · medium confidence
Nuclei v3 SDK and library support
The \lib\ package now provides a public SDK for embedding Nuclei into Go applications. This includes the \NucleiEngine\ and \ThreadSafeNucleiEngine\ for running scans, with configuration options for templates, workflows, concurrency, rate limiting, and result callbacks. The \README.md\ provides usage examples, and tests in \config\_test.go\, \multi.go\, and \sdk\_test.go\ validate the new functionality.
lib · high confidence
Repository structure and build configuration initialized
The repository now includes a complete set of foundational files that define the project's structure and build process. A \.gitignore\ file is added to exclude build artifacts, templates, and generated documentation. A \Dockerfile\ and \Dockerfile.goreleaser\ are introduced to support containerized builds and releases. The \Makefile\ is added to automate common development tasks such as building, testing, and fuzzing. Additionally, a \.goreleaser.yml\ configuration file is provided to manage the release process, including multi-architecture Docker image builds and GitHub releases. Documentation files including \CLAUDE.md\, \CONTRIBUTING.md\, \DEBUG.md\, \DESIGN.md\, \FUZZING.md\, \LICENSE.md\, and \README.md\ (in multiple languages) are also added to guide users and contributors.
(repo-wide) · high confidence
Sandboxed YAML preprocessing with include directives and strict decoding
The YAML utility package now provides a preprocessing step that resolves \\# !include:\ directives by inlining referenced YAML files. This process is sandboxed: by default, included files must reside within the template's own directory or the configured template base directory, and hard links are rejected. The system also enforces a maximum include depth (32) and detects circular references. Additionally, the package introduces a strict YAML decoder that rejects unknown struct fields and duplicate mapping keys, while the default decoder maintains backward-compatible lax behavior for duplicate keys.
pkg/utils/yaml · high confidence
Support downloading custom templates from Azure Blob Storage and GitLab
Users can now download custom templates from Azure Blob Storage and GitLab repositories, in addition to the existing GitHub and AWS S3 providers. The new Azure provider fetches templates from an Azure container, while the GitLab provider downloads templates from specified projects. Both implementations include strict path-traversal protection to ensure downloaded files remain within the designated template directory.
pkg/external · high confidence
Support for downloading and parsing Swagger 2.0 API specifications
Users can now provide remote or local Swagger 2.0 (OpenAPI 2.0) API specifications to the tool. The new downloader fetches and validates the spec, automatically inferring the host and scheme from the source URL, and the parser converts the 2.0 schema to 3.0 for internal processing, enabling automated request generation from these API definitions.
pkg/input/formats/swagger · high confidence
Support for multi-document YAML inputs with ytt templating
Users can now provide YAML input files containing multiple documents (separated by ---) and use ytt templating to inject variables from the CLI or configuration files. The new \YamlMultiDocFormat\ parser processes these inputs, applying text templating when enabled, and extracts raw HTTP requests for each document. This enables more flexible input handling for tools like Proxify, allowing dynamic content generation via ytt templates.
pkg/input/formats/yaml · high confidence
Support for static and dynamic authentication strategies
The auth provider now supports multiple authentication strategies, including Basic, Bearer Token, Header, Cookie, and Query-based auth. Static credentials can be loaded from a YAML file, while dynamic secrets can be resolved at runtime using templates and variables. The implementation includes a new \authx\ package with strategy implementations and a \Dynamic\ struct that handles lazy fetching and concurrent-safe resolution of dynamic secrets.
pkg/authprovider/authx · high confidence
Removals
Removed legacy matcher implementation
The legacy matcher implementation in the \pkg/matchers\ package has been removed. This includes the deletion of \compile.go\, \match.go\, and \matchers.go\, which previously handled HTTP response matching for status codes, sizes, words, and regexes. Users relying on these specific matcher types will need to adopt the new matching logic provided by the updated package.
pkg/matchers · high confidence
Architecture
HTTP protocol refactored into new modular files
The HTTP protocol implementation has been reorganized into dedicated files for request building, clustering, and operator handling. This refactoring improves code maintainability and testability by separating concerns, with new files including build\_request.go, cluster.go, and operators.go, each accompanied by corresponding test files to ensure functionality is preserved.
pkg/protocols/http · high confidence
Refactor headless engine into modular components
The headless engine code in pkg/protocols/headless/engine has been refactored into separate, modular files (action.go, action\_types.go, engine.go, hijack.go, http\_client.go, instance.go, page.go, page\_actions.go, rules.go, util.go). This restructuring organizes the headless browser logic into distinct responsibilities: action definitions and types, browser and instance management, HTTP client configuration, page interaction, and request/response rule handling. Users benefit from a more maintainable and testable codebase, which supports the addition of new headless actions and improved stability.
pkg/protocols/headless/engine · high confidence
Behavioural changes
Add caching for compiled regex, DSL, and JSON expressions
The extractors package now caches compiled regular expressions, DSL expressions, and JSON queries to improve performance. The cache is backed by \gcache\ and \govaluate\, with configurable capacities for regex and DSL caches. A negative regex group index is now rejected at compile time to prevent index-out-of-range panics during extraction.
pkg/operators/extractors · high confidence
Added result writing helper with honeypot suppression support
A new \WriteResult\ helper in \pkg/protocols/common/helpers/writer\ manages the output of scan results. It handles writing results to the output writer, creating issues on a provided tracker client, and incrementing progress counters. Notably, it supports suppressing output when a honeypot is detected, which helps reduce scan noise by preventing false-positive results from being written or counted.
pkg/protocols/common/helpers/writer · medium confidence
Enforce execution-scoped network policies for SMB and goimpacket dialers
Added the gptransport and smbsession Go packages to the JavaScript library layer. gptransport installs a global hook on goimpacket's TCP dialer to require an execution-bound dialer, ensuring all connections are validated against the host allowlist. smbsession provides a high-level SMB client that enforces share name validation, path normalization, and read/tree-walk limits, while also checking host policies during connection. These changes prevent cross-scan connection leaks and restrict SMB operations to authorized hosts and paths.
pkg/js/libs/gptransport, pkg/js/libs/smbsession · high confidence
Fix WebSocket path resolution when merging template and target URLs
The WebSocket protocol handler now correctly resolves the request path by prioritizing the path defined in the template over the target URL's path. Previously, the path handling could lead to incorrect URL construction; this change ensures that if a template specifies a path, that path is used, otherwise the target's path is used. This fix addresses a bug where WebSocket requests were not correctly targeting the intended endpoints, particularly for templates like Jenkins CLI or Grafana Live where the path is critical.
pkg/protocols/websocket · high confidence
GitLab tracker now supports duplicate issue detection and granular filtering
The GitLab issue tracker integration has been updated to prevent duplicate reports by checking for existing issues with matching titles before creating new ones. When a duplicate is found, the system reopens closed issues or adds a note to existing ones. This change also introduces configuration options for controlling the duplicate check behavior, including page size and maximum pages for searching. Additionally, the integration now supports granular filtering via allow-list and deny-list configurations, allowing users to control which events are sent to the tracker.
pkg/reporting/trackers/gitlab · high confidence
Headless protocol refactored into new package structure
The headless protocol implementation has been reorganized into a new package structure, splitting the logic into dedicated files for the request definition, operator handling, and execution. This refactoring introduces explicit support for XPath and JSON extractors within headless templates, allowing users to parse and extract data from HTML and JSON responses using these specific extraction methods. The change also ensures that template context variables are correctly passed and available for evaluation during headless request execution, resolving previous issues where variables were not accessible within headless templates.
pkg/protocols/headless · high confidence
Improved HTTP protocol stop-at-first-match handling and utility functions
The HTTP protocol now uses a dedicated \StopAtFirstMatchHandler\ to manage concurrent requests and ensure that execution stops immediately upon finding the first match, preventing unnecessary work. Additionally, a new \GetInteractshURLSFromEvent\ utility function has been added to extract Interactsh URLs from event data, supporting the broader template execution logic.
pkg/protocols/http/httputils · medium confidence
Improved host error handling and context cancellation support
The host error cache now supports context cancellation, ensuring that failures caused by parent scan cancellation or deadline expiration are not counted against the host. It also introduces a new \Remove\ method to explicitly remove hosts from the cache, and a \MarkFailedOrRemove\ method that resets the error count on success. Additionally, the cache now considers the protocol type when tracking errors, and fixes duplicate logging for permanent errors.
pkg/protocols/common/hosterrorscache · high confidence
Improved variable dumping and added matcher exclusion utilities
The \vardump\ package has been refactored to use the \godump\ library for pretty-printing variables, featuring custom color themes and a 255-character truncation limit. Additionally, a new \excludematchers\ utility has been introduced to allow users to exclude specific matchers by template ID, matcher name, or wildcard patterns.
pkg/protocols/common/utils · high confidence
Input transformation and normalization for multi-protocol templates
The \pkg/input\ package now includes a new \transform.go\ module that normalizes and validates input data based on the target protocol type (e.g., DNS, HTTP, File, Websocket). This change ensures that inputs are correctly formatted—such as adding default ports, validating file paths, or converting hostnames to URLs—before being processed by protocol executors. The implementation is accompanied by comprehensive unit tests in \transform\_test.go\ that verify the correct transformation of various input types.
pkg/input · high confidence
Introduce DNS client pooling for concurrent engine support
Added a new DNS client pool implementation in \pkg/protocols/dns/dnsclientpool/clientpool.go\ to support concurrent Nuclei engines running in the same process. The new code manages a pool of \retryabledns.Client\ instances, caching them by a hash of their configuration (retries, resolvers, and proxy). The \Init\ function creates a default client, while the \Get\ function retrieves or creates clients based on specific configurations, allowing the system to handle multiple simultaneous DNS requests with different resolver or proxy settings.
pkg/protocols/dns/dnsclientpool · medium confidence
Introduce format abstraction for report generation
The reporting format layer now uses a ResultFormatter interface to generate report content, allowing different output formats (e.g., Markdown) to be supported via separate implementations. This change introduces a new \format\ package containing \format.go\ and \format\_utils.go\, which define the \ResultFormatter\ interface and utility functions like \CreateReportDescription\ and \CreateTemplateInfoTable\. The implementation includes specific handling for request/response truncation, metadata hooks, and markdown injection prevention in the generated reports.
pkg/reporting/format · high confidence
Introduces a centralized scan context for managing state and events
A new \ScanContext\ type has been added to \pkg/scan\ to centralize the management of scan state, events, and callbacks. This context holds the scan's input, error and warning logs, and a collection of results, while providing thread-safe methods to log events, errors, and warnings. This change supports context cancellation and provides a unified way to track scan progress and outcomes.
pkg/scan · high confidence
Introduces per-execution protocol state management and HTTP client pooling
The \protocolstate\ package is refactored to manage state per execution ID, enabling concurrent Nuclei engines to operate independently within the same process. A new \HTTPPool\ provides lock-free, concurrent-safe HTTP client and transport caching with automatic eviction of idle connections, improving performance and reducing resource leaks. Additionally, the system now tracks execution context, enforces local file access and network policy restrictions per execution, and initializes JavaScript runtimes with security defaults.
pkg/protocols/common/protocolstate · high confidence
JavaScript protocol execution and safety improvements
The JavaScript protocol implementation was refactored to enforce security and improve reliability. Unverified templates are now refused during execution to prevent the running of unsigned code. Additionally, argument evaluation errors are handled gracefully without panicking, and the rendering of interactsh URLs in payloads is corrected to ensure proper marker allocation and evaluation.
pkg/protocols/javascript · high confidence
Per-host HTTP client pooling and connection reuse
The HTTP client pool now creates and caches a separate client per host, enabling connection reuse and significantly improving performance for scans targeting many hosts. The change introduces per-host connection statistics tracking, a bounded LRU cache for detecting HTTP-to-HTTPS port mismatches, and a per-host rate-limiting pool. Additionally, the codebase adds tests for the new client pool, host normalization, and the HTTP-to-HTTPS tracker.
pkg/protocols/http/httpclientpool · high confidence
Refactor input provider architecture with new interfaces and implementations
The input provider system has been refactored to support multiple input formats (list, OpenAPI, Swagger, Burp, Postman, etc.) through a unified \InputProvider\ interface. A new \SimpleInputProvider\ handles basic URL lists, while the \NewInputProvider\ factory now dynamically selects the appropriate provider (e.g., \HttpInputProvider\ for complex formats) based on the \InputFileMode\ option. This change introduces a more modular and extensible way to process various input sources, including direct fuzzing for OpenAPI/Swagger targets and HTTP-based input handling.
pkg/input/provider · high confidence
Refactored JavaScript compiler with pooled runtime management and context-aware execution
The JavaScript execution engine has been refactored to use a pooled runtime architecture, introducing a new \pkg/js/compiler\ package that manages Goja runtime instances via a concurrency pool. This change adds support for context cancellation and execution deadlines, ensuring that long-running or stuck scripts are properly interrupted and cleaned up. The compiler now handles runtime lifecycle, including preparation, execution, and cleanup, with specific attention to preventing concurrent map panics by abandoning and discarding runtimes that fail to terminate within a grace period. Additionally, the implementation enforces local file access restrictions for \require\ calls and provides a robust mechanism for exporting results and handling panics gracefully.
pkg/js/compiler · high confidence
Refactored disk-based template catalog to support embedded filesystems
The disk catalog implementation has been refactored to support both standard disk paths and embedded filesystems (fs.FS). This change introduces a new DiskCatalog struct that can operate on either the local filesystem or an embedded fs.FS, allowing template resolution to work consistently across different storage backends. The refactoring includes path resolution logic that handles both absolute and relative paths, with specific handling for glob patterns and directory traversal. Additionally, the code now uses canonical path containment checks to prevent sibling-prefix path aliasing issues, ensuring that template paths are correctly resolved regardless of the underlying storage mechanism.
pkg/catalog/disk · high confidence
Refactored expression evaluation to prevent execution of resolved values
The expression evaluation logic in the protocols layer has been refactored to ensure that resolved template values are never compiled or executed as expressions. Previously, if a template variable contained a string like '{{md5("Hello")}}', the system would attempt to evaluate it as a new expression, which could lead to unexpected behavior or security issues. The new implementation in \pkg/protocols/common/expressions\ distinguishes between user-authored expressions (which are evaluated) and resolved values (which are treated as literals). This change also introduces improved handling of unresolved variable markers through encoding functions, ensuring that placeholders like \{{contact\_id}}\ are preserved correctly even when passed to functions like \base64\ or \hex\_encode\. Additionally, the codebase now relies on the \govaluate\ library for expression parsing, providing a more robust and secure evaluation engine.
pkg/protocols/common/expressions · high confidence
Refactored matcher implementation with improved validation and fuzz testing
The matcher logic in \pkg/operators/matchers\ has been refactored into a new, cleaner structure. This includes a new \CompileMatchers\ method that handles initial setup, regex compilation, and DSL expression evaluation with shared caching. A \Validate\ method was added to enforce strict field validation per matcher type (e.g., ensuring \Status\ is not used with \XPath\ matchers). Additionally, fuzz testing infrastructure (\fuzz.go\, \fuzz\_harness.go\) and seed corpus files were added to exercise the matcher compilation and matching logic, improving robustness against malformed inputs.
pkg/operators/matchers · high confidence
Refactored output system with new writer interfaces and formatting
The output subsystem has been refactored to use a new \Writer\ interface and \StandardWriter\ implementation, enabling multiple concurrent output destinations via a \MultiWriter\. This change introduces structured formatting for JSON and screen output, adds support for storing responses, and integrates honeypot detection to suppress false positives. Additionally, the output now includes additional fields such as port, IP, scheme, and URL in JSON results, and supports redacting sensitive information from logs.
pkg/output · high confidence
Refactored variable evaluation with lazy evaluation and scope-based rendering
The variable evaluation logic has been refactored to support lazy evaluation of template variables that reference undefined parameters or runtime data. A new \Scope\ type distinguishes between terminal data values and template-derived values, allowing the system to defer evaluation of variables that depend on other variables or runtime context. This change introduces a \LazyEval\ flag that triggers deferred evaluation, ensuring that variables referencing undefined parameters or dynamic data are only evaluated when needed. The implementation includes a \Scope\ struct that manages variable sources (OptionsMap, DynamicMap, ProtocolMap, etc.) and handles re-evaluation of non-linear variable dependencies. Benchmarks and tests have been added to validate the new evaluation behavior.
pkg/protocols/common/variables · high confidence
Fixes
Fix memory blowup in multiproto execution
The utility function FillPreviousEvent in pkg/tmplexec/utils/utils.go was updated to prevent memory blowup during multiproto execution. The implementation ensures that previous events are correctly merged without duplicating prefixes, addressing a memory management issue in the template execution logic.
pkg/tmplexec/utils · medium confidence
Test coverage
Added scale regression and SDK unit tests; Introduces fuzz testing and robust HTTP request/response handling.
Dependencies
Updated Go dependencies and upgraded to Go 1.26
The project's Go module configuration has been updated to require Go 1.26, and numerous dependencies have been upgraded. Key updates include \github.com/go-git/go-git/v5\ to v5.19.1, \github.com/projectdiscovery/utils\ to v0.11.1, \github.com/projectdiscovery/retryablehttp-go\ to v1.3.21, and \github.com/projectdiscovery/dsl\ to v0.8.20. The \go.sum\ file has been regenerated to reflect these changes.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 60.
Lenses
- Code Health 81
- Architecture 100
- Maturity 61
- Readiness 74
- Security 53
- Event-Driven 100
- Accessibility 57
Changes since last survey
- 300 commits — 196 feature/other, 104 fixes
By area
- (repo) — 63 commits
- (root) — 58 commits
- pkg/protocols — 42 commits
- pkg/js — 24 commits
- .github/workflows — 17 commits
- pkg/fuzz — 15 commits
- internal/runner — 14 commits
- pkg/catalog — 12 commits
- pkg/templates — 8 commits
- internal/tests — 6 commits
- pkg/utils — 6 commits
- pkg/core — 5 commits
- pkg/input — 5 commits
- cmd/nuclei — 4 commits
- pkg/operators — 4 commits
- pkg/reporting — 4 commits
- lib/multi_bench_test.go — 2 commits
- lib/sdk_test.go — 2 commits
- pkg/tmplexec — 2 commits
- integration_tests/protocols — 1 commit
Notable commits
- fix: Fix case-insensitive word matcher missing dynamic (rendered) values (#7523)
- fix: Fix connection reuse + port pre-flight (#6715)
- fix: Merge branch 'dev' into fix/encoding-hides-unresolved-vars
- fix: Merge pull request #6760 from JawsKim/fix/issue-5579-large-exclusion-hang
- fix: Merge pull request #6944 from maxwolf8852/fix/noHostErrors-panic
- fix: Merge pull request #7018 from projectdiscovery/dwisiswant0/chore/go-fix
- fix: Merge pull request #7020 from Pitrat-wav/fix-docs-links-proper
- fix: Merge pull request #7026 from n3integration/fix/executor-concurrency-improvement
- fix: Merge pull request #7033 from projectdiscovery/fix/encoding-hides-unresolved-vars
- fix: Merge pull request #7043 from projectdiscovery/dwisiswant0/fix/http/isolate-project-cache-keys-by-scheme-host
- fix: Merge pull request #7045 from projectdiscovery/dwisiswant0/fix/utils/normalize-unbracketed-IPv6-literals-for-probing
- fix: Merge pull request #7125 from usernametooshort/fix/time-delay-missing-custom-headers
- fix: Merge pull request #7129 from usernametooshort/fix/host-spray-skip-unresponsive-early
- fix: Merge pull request #7145 from projectdiscovery/dwisiswant0/fix/runner/use-Print-instead-to-listAvailableStoreTags
- fix: Merge pull request #7215 from sandiyochristan/fix/use-crypto-rand-in-js-globals
- fix: Merge pull request #7286 from projectdiscovery/4685-fix-fhr-redirect-port-normalization
- fix: Merge pull request #7287 from projectdiscovery/4927-fix-elasticsearch-ip-host-validation
- fix: Merge pull request #7294 from mikhail5555/fix/data-race-condition-global-variable
- fix: Merge pull request #7298 from projectdiscovery/7295-dynamic-auth-flow-fix
- fix: Merge pull request #7322 from projectdiscovery/dwisiswant0/fix/interactsh/serialize-InternalEvent-access
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
projectdiscovery/nuclei was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 64bc83e004553d652c41c086685f56e5f878cfd3 — the exact code this score is about.
- Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer latest.