CVE-2025-11864: Nucleoidai Nucleoid
High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability was identified in NucleoidAI Nucleoid up to 0.7.10. The impacted element is the function extension.apply of the file /src/cluster.ts of the component Outbound Request Handler. Such manipulation of the argument https/ip/port/path/headers leads to server-side request forgery. The attack may be performed from remote.
Affected products
- Nucleoidai Nucleoid: version 0.7.0 only; version 0.7.1 only; version 0.7.2 only; version 0.7.3 only; version 0.7.4 only; version 0.7.5 only; …
Published 2025-10-16. Last modified 2026-10-09.