CVE•Published 2026-06-03•Modified 2026-07-22•0 articles on news•5 live references•NVD data

CVE-2026-8888Securly · Securly

Vulnerability data via NVD (ingested)

CVSS v3.1
7.5
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS percentile
35
Exploit Prediction Scoring System · top 65% of all CVEs
Description

Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on all browsing.

Timeline
Published 2026-06-03
Modified 2026-07-22

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub (8)

nomi-sec/PoC-in-GitHubunknown
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
★ 8,087·updated 2d ago
Cyber-note/Full-Bug-Bounty-Hunting-Methodology-2026unknown
How To approach recon on real targets — from passive enumeration to origin IP discovery. Covers tools, automation, and the logic behind each phase.
★ 414·updated 2mo ago
grisuno/LazyOwnPython
LazyOwn RedTeam/APT Framework is the first RedTeam Framework with an AI-powered C&C, featuring rootkits to conceal campaigns, undetectable malleable implants compatible with Window…
★ 227·updated 4d ago
7WaySecurity/ai_osintunknown
🤖 Curated AI OSINT resources — Google dorks, Shodan queries, GitHub dorks, and techniques to discover exposed LLM endpoints, leaked AI API keys, misconfigured vector databases, an…
★ 165·updated 3mo ago
melinhades/Celeste-AI-Diary-Companion-BlogHTML
posting blog and writing diary with madeline from celeste
★ 127·updated 3d ago
eldarshiraliyev/BugScannerPython
🐛 Advanced web vulnerability scanner with 5-rule false-positive reduction, WAF evasion, and modern HTML reports
★ 98·updated 1w ago
fstr415/TikTok-Poll-Voting-ExploitJavaScript
Modern day TikTok exploit that allows you to fake having the "Voted on" text under any tiktok for anyone to see, no matter if the tiktok has the poll or not. Anything you want can …
★ 83·updated 2mo ago
3sk1nt4n/arguswatch-aiPython
AI-Agentic Threat Intelligence - 39 collectors, 7 AI agents, 3-link proof chain, D1-D5 exposure scoring
★ 70·updated 6mo ago
We haven't classified any articles referencing CVE-2026-8888 yet. The external references above still apply.