← Volver al buscador de CVEs

CVE-2026-72912

Descripción

CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef-s pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CPU when a malformed #recipe= URL fragment containing a large number of unmatched quote characters reaches Utils.parseRecipeConfig(). The function synchronously applies a complex global regular expression that may perform heavy backtracking before rejecting the input, causing the victim-s browser tab to freeze during startup for seconds or longer. No code execution, data exfiltration, or privilege escalation occurs. This issue is fixed in version 11.3.0.

CVSS 4.3EPSS 0.185%Riesgo 0.44
Ver fuente
Publicación
2026-08-10 21:17:26
Última modificación
2026-08-10 21:17:26
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L