Skip to content
Fedora Nuclei Vulnerabilities: Cross-site Scripting and Information Disclosure Risks

Fedora Nuclei Vulnerabilities: Cross-site Scripting and Information Disclosure Risks

First seen 22 Jul 2026, 09:46 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 23, 2026 at 09:23 UTC

Fedora has released security updates addressing critical vulnerabilities in the Nuclei scanner. CVE-2026-5160, published on April 15, 2026, involves cross-site scripting due to improper URL validation, affecting multiple versions of Nuclei. Additionally, CVE-2026-41646, published on May 8, 2026, allows information disclosure via JavaScript template local file access bypass. Users of Fedora 43 and 44 are advised to apply the updates to mitigate these risks. The vulnerabilities could lead to broader security issues if exploited, particularly in environments with overly broad permissions. The updates can be installed using the 'dnf' package manager. The vulnerabilities highlight the importance of maintaining least privilege access in Linux systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 50d ago How this analysis works

Timeline

2026-04-15
CVE-2026-5160 published
Cross-site scripting vulnerability identified in Nuclei due to improper URL validation.
Linuxsecurity
2026-05-08
CVE-2026-41646 published
Information disclosure vulnerability discovered in Nuclei allowing local file access bypass.
Linuxsecurity
2026-06-04
CVE-2026-45287 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-22
Security updates released for Fedora
Fedora 43 and 44 users are urged to apply updates to address critical vulnerabilities in Nuclei.
Linuxsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-41646 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed