---
id: CVE-2026-76819
title: >-
  Rejected reason: Further research determined the issue results from a
  dependency.
summary: >-
  Rejected reason: Further research determined the issue results from a
  dependency.
severity: high
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T17:17:25.230'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76819'
tags:
  - nvd
  - ghsa
  - go
  - osv
ingestedAt: '2026-09-22T18:08:12.466Z'
aliases:
  - GHSA-vxg7-f2jj-jmqm
ecosystem: go
vendor: projectdiscovery
product: github.com/projectdiscovery/nuclei/v3
affected:
  - 'github.com/projectdiscovery/nuclei/v3 >= 3.0.0, < 3.10.0'
patched:
  - github.com/projectdiscovery/nuclei/v3 3.10.0
cvss: 8.6
cvssSource: ghsa
cwe:
  - CWE-94
  - CWE-787
references:
  - url: >-
      https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-vxg7-f2jj-jmqm
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76819'
  - url: 'https://github.com/projectdiscovery/nuclei/pull/7467'
  - url: 'https://github.com/projectdiscovery/nuclei/pull/7514'
  - url: >-
      https://github.com/projectdiscovery/nuclei/commit/1fe6025b966cbb95ed4d9f40abfb629b6cbd27b2
  - url: 'https://github.com/projectdiscovery/nuclei/releases/tag/v3.10.0'
  - url: 'https://github.com/advisories/GHSA-vxg7-f2jj-jmqm'
  - url: 'https://github.com/projectdiscovery/nuclei'
---

## Overview

Rejected reason: Further research determined the issue results from a dependency.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-76819)

Affected packages:

- `github.com/projectdiscovery/nuclei/v3 >= 3.0.0, < 3.10.0`

Patched in:

- `github.com/projectdiscovery/nuclei/v3 3.10.0`

Source: https://github.com/advisories/GHSA-vxg7-f2jj-jmqm
