CyberRota
← Ana sayfaya dön

CVE-2026-8888

HIGH · CVSS 7.5 EPSS %0.43

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-03T19:16:39.807 · Çekilme zamanı: 2026-06-30T12:09:17.393593+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-8888
Severity
HIGH
CVSS
7.5
EPSS
%0.43
Chrome Java

Orijinal NVD Açıklaması

Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on all browsing.