CVE-2026-8889: CWE-328 in Securly Securly Chrome Extension
Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist matching (12,352 hashes).
AI Analysis
Technical Summary
CVE-2026-8889 describes a cryptographic weakness in the Securly Chrome Extension version 3.0.7, where SHA-1 hashing is used for URL matching against IWF CSAM and CIPA blocklists. SHA-1 is considered deprecated due to its vulnerabilities to collision attacks, which may undermine the integrity of the matching process. The vulnerability is classified under CWE-328 (Use of Weak Hash). No CVSS score or vendor patch information is currently available, and no exploits have been reported.
Potential Impact
The use of SHA-1 hashing may allow attackers to produce hash collisions, potentially bypassing URL matching controls for child safety and content filtering. This could reduce the effectiveness of the extension's blocking mechanisms. However, no active exploitation has been reported, and the exact impact depends on the attacker's ability to generate collisions relevant to the hashed URLs.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should monitor official advisories from Securly and CERT. No immediate workaround or mitigation is provided in the advisory.
CVE-2026-8889: CWE-328 in Securly Securly Chrome Extension
Description
Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist matching (12,352 hashes).
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-8889 describes a cryptographic weakness in the Securly Chrome Extension version 3.0.7, where SHA-1 hashing is used for URL matching against IWF CSAM and CIPA blocklists. SHA-1 is considered deprecated due to its vulnerabilities to collision attacks, which may undermine the integrity of the matching process. The vulnerability is classified under CWE-328 (Use of Weak Hash). No CVSS score or vendor patch information is currently available, and no exploits have been reported.
Potential Impact
The use of SHA-1 hashing may allow attackers to produce hash collisions, potentially bypassing URL matching controls for child safety and content filtering. This could reduce the effectiveness of the extension's blocking mechanisms. However, no active exploitation has been reported, and the exact impact depends on the attacker's ability to generate collisions relevant to the hashed URLs.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should monitor official advisories from Securly and CERT. No immediate workaround or mitigation is provided in the advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- certcc
- Date Reserved
- 2026-05-18T20:43:53.154Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://kb.cert.org/vuls/id/595768","vendor":"CERT"}]
Threat ID: 6a207a8ee29bf47b50dc56a5
Added to database: 06/03/2026, 19:03:42 UTC
Last enriched: 06/10/2026, 19:40:33 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 69
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.