Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7w3m-2pw9-mg8x

Опубликовано: 03 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on all browsing.

Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on all browsing.

EPSS

Процентиль: 35%
0.00432
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333
CWE-917

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on all browsing.

EPSS

Процентиль: 35%
0.00432
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333
CWE-917