CVE-2026-8888: CWE-1333 in Securly Securly Chrome Extension
Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on all browsing.
AI Analysis
Technical Summary
The vulnerability in Securly Chrome Extension version 3.0.7 involves insecure retrieval of config.json via HTTP and unsafe compilation of server-supplied patterns into RegExp objects without complexity checks. An attacker positioned on the network path can manipulate these patterns to trigger catastrophic backtracking in the regular expression engine, resulting in a denial of service condition that affects all browsing sessions using the extension.
Potential Impact
An attacker with the ability to intercept network traffic can cause the extension to enter a state of catastrophic backtracking by injecting crafted regular expression patterns. This leads to denial of service on all browsing activities, impacting availability. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
No official patch or remediation is currently available for this vulnerability. Users should monitor the vendor advisory for updates. As the extension downloads configuration over HTTP, using network protections such as HTTPS enforcement or VPNs may reduce exposure to on-path attackers, but no vendor-provided mitigation is confirmed.
CVE-2026-8888: CWE-1333 in Securly Securly Chrome Extension
Description
Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on all browsing.
CVSS v3.1
Score 7.5high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Securly Chrome Extension version 3.0.7 involves insecure retrieval of config.json via HTTP and unsafe compilation of server-supplied patterns into RegExp objects without complexity checks. An attacker positioned on the network path can manipulate these patterns to trigger catastrophic backtracking in the regular expression engine, resulting in a denial of service condition that affects all browsing sessions using the extension.
Potential Impact
An attacker with the ability to intercept network traffic can cause the extension to enter a state of catastrophic backtracking by injecting crafted regular expression patterns. This leads to denial of service on all browsing activities, impacting availability. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
No official patch or remediation is currently available for this vulnerability. Users should monitor the vendor advisory for updates. As the extension downloads configuration over HTTP, using network protections such as HTTPS enforcement or VPNs may reduce exposure to on-path attackers, but no vendor-provided mitigation is confirmed.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- certcc
- Date Reserved
- 2026-05-18T20:40:05.298Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://kb.cert.org/vuls/id/595768","vendor":"CERT"}]
Threat ID: 6a207a8ee29bf47b50dc56a2
Added to database: 06/03/2026, 19:03:42 UTC
Last enriched: 06/10/2026, 19:33:23 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 114
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.