CVEPublished 2026-06-03Modified 2026-07-220 articles on news5 live referencesNVD data

CVE-2026-8888Securly · Securly

Vulnerability data via NVD (ingested)

CVSS v3.1
7.5
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS percentile
35
Exploit Prediction Scoring System · top 65% of all CVEs
Description

Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on all browsing.

Timeline
Published 2026-06-03
Modified 2026-07-22

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub (8)

0xSteph/pentest-aiPython
Offensive-security MCP server with 205 wrapped tools, 17 specialist agents, and 60 SPA-aware probes for OWASP Top 10. CLI + MCP, BYO LLM. No API key needed on MCP path.
★ 1,442·updated 3w ago
Cyber-note/Full-Bug-Bounty-Hunting-Methodology-2026unknown
How To approach recon on real targets — from passive enumeration to origin IP discovery. Covers tools, automation, and the logic behind each phase.
★ 342·updated 3w ago
grisuno/LazyOwnPython
LazyOwn RedTeam/APT Framework is the first RedTeam Framework with an AI-powered C&C, featuring rootkits to conceal campaigns, undetectable malleable implants compatible with Window…
★ 215·updated 3d ago
7WaySecurity/ai_osintunknown
🤖 Curated AI OSINT resources — Google dorks, Shodan queries, GitHub dorks, and techniques to discover exposed LLM endpoints, leaked AI API keys, misconfigured vector databases, an…
★ 150·updated 1mo ago
fstr415/TikTok-Poll-Voting-ExploitJavaScript
Modern day TikTok exploit that allows you to fake having the "Voted on" text under any tiktok for anyone to see, no matter if the tiktok has the poll or not. Anything you want can …
★ 81·updated 3w ago
3sk1nt4n/arguswatch-aiPython
AI-Agentic Threat Intelligence - 39 collectors, 7 AI agents, 3-link proof chain, D1-D5 exposure scoring
★ 66·updated 4mo ago
yks0000/starred-repo-tocGo
Generates Markdown table for all Starred Repositories by a GitHub user.
★ 46·updated 3d ago
lsszz2100/VibeHackingJavaScript
A Collection of Repositories, Videos, Books, and Lecture Materials to Learn Security & Hacking with AI in a Fun Way
★ 40·updated 4d ago
We haven't classified any articles referencing CVE-2026-8888 yet. The external references above still apply.