CVE-2026-8888 PUBLISHED

CVE-2026-8888

Assigner: certcc
Reserved: 18.05.2026 Published: 03.06.2026 Updated: 03.06.2026

Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on all browsing.

Product Status

Vendor Securly
Product Securly Chrome Extension
Versions
  • affected from 0 to 3.0.7 (incl.)

References

Problem Types

  • CWE-1333