Version 3.0.7 of the Securly Chrome Extension downloads...
High severity
Unreviewed
Published
Jun 3, 2026
to the GitHub Advisory Database
•
Updated Jun 5, 2026
Description
Published by the National Vulnerability Database
Jun 3, 2026
Published to the GitHub Advisory Database
Jun 3, 2026
Last updated
Jun 5, 2026
Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on all browsing.
References