ProjectDiscovery's nuclei-templates repository received two new vulnerability detection submissions: one for an Odoo website information disclosure issue and another for CVE-2026-3055. The Odoo template, submitted in pull request #15693 by aushack, adds a check intended to identify exposed information on Odoo websites. The contributor said the template was validated against both a vulnerable target and a patched or non-vulnerable target to confirm detection accuracy and reduce false positives.
A separate pull request, #15721, submitted by shaikhyaser, proposes a Nuclei template for CVE-2026-3055, a flaw discussed as potentially requiring a SAML-enabled environment and possibly involving memory leakage. Review comments in the repository show maintainers questioned whether the memory leak had been successfully reproduced, indicating the template's effectiveness and exploitability were still being evaluated and that the submission had not yet been merged at the time of review.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A separate GitHub pull request (#15721) was opened in the projectdiscovery/nuclei-templates repository for a Nuclei template labeled CVE-2026-3055. Discussion on the pull request indicated the issue may require a SAML-enabled environment and involve a memory leak, with maintainers questioning whether the contributor had successfully reproduced the behavior.
A GitHub pull request (#15693) was opened in the projectdiscovery/nuclei-templates repository to add a Nuclei template for detecting an Odoo website information disclosure issue. The contributor said the template was validated against both vulnerable and patched or non-vulnerable targets to confirm accurate detection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.