PT-2026-46053 · Securly · Securly Chrome Extension

Published

2026-06-03

·

Updated

2026-06-03

·

CVE-2026-8888

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on all browsing.

Related Identifiers

CVE-2026-8888

Affected Products

Securly Chrome Extension