All verified exploits

CVE-2026-29042 Shell Runtime Command Injection

Deterministic critical Nuclio Added cve-verified-cve-2026-29042

Proves unauthenticated command injection via the X-Nuclio-Arguments HTTP header, which is passed directly to sh -c without sanitization. A math canary confirms arbitrary command execution.

Is your app exploitable through CVE-2026-29042?

Scan your domain free