CVE-2026-72912

Source
https://cve.org/CVERecord?id=CVE-2026-72912
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-72912.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-72912
Aliases
  • GHSA-w74r-jxjh-gwr6
Published
2026-08-10T21:02:16.375Z
Modified
2026-08-12T04:24:51.545057519Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVSS Calculator
Summary
CyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaustion when parsing a malformed #recipe= URL
Details

CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CPU when a malformed #recipe= URL fragment containing a large number of unmatched quote characters reaches Utils.parseRecipeConfig(). The function synchronously applies a complex global regular expression that may perform heavy backtracking before rejecting the input, causing the victim's browser tab to freeze during startup for seconds or longer. No code execution, data exfiltration, or privilege escalation occurs. This issue is fixed in version 11.3.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72912.json",
    "cwe_ids": [
        "CWE-1333",
        "CWE-400"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/gchq/cyberchef

Affected ranges

Type
GIT
Repo
https://github.com/gchq/cyberchef
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "11.3.0"
        }
    ]
}

Affected versions

10.*
10.14.0
10.6.0
v10.*
v10.0.0
v10.0.1
v10.1.0
v10.10.0
v10.11.0
v10.12.0
v10.12.1
v10.13.0
v10.14.0
v10.15.0
v10.15.1
v10.16.0
v10.17.0
v10.17.1
v10.18.0
v10.18.1
v10.18.2
v10.18.3
v10.18.4
v10.18.5
v10.18.6
v10.18.7
v10.18.8
v10.18.9
v10.19.1
v10.19.2
v10.19.3
v10.19.4
v10.2.0
v10.20.0
v10.21.0
v10.22.0
v10.22.1
v10.23.0
v10.24.0
v10.3.0
v10.4.0
v10.5.0
v10.5.1
v10.5.2
v10.6.0
v10.7.0
v10.8.0
v10.8.1
v10.8.2
v10.9.0
v11.*
v11.0.0
v11.1.0
v11.2.0
v5.*
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.1.2
v5.1.3
v5.10.0
v5.10.1
v5.10.2
v5.10.3
v5.10.4
v5.10.5
v5.10.6
v5.10.7
v5.11.0
v5.11.1
v5.11.2
v5.11.3
v5.11.4
v5.11.5
v5.11.6
v5.11.7
v5.12.0
v5.12.1
v5.12.3
v5.12.4
v5.13.0
v5.13.1
v5.14.0
v5.15.0
v5.16.0
v5.16.1
v5.16.2
v5.16.3
v5.17.0
v5.18.0
v5.18.1
v5.19.0
v5.19.1
v5.19.2
v5.19.3
v5.2.0
v5.2.1
v5.2.2
v5.2.3
v5.2.4
v5.20.0
v5.3.0
v5.3.1
v5.3.2
v5.3.3
v5.3.4
v5.3.5
v5.4.0
v5.4.1
v5.5.0
v5.6.0
v5.7.0
v5.7.1
v5.7.2
v5.7.3
v5.8.0
v5.9.0
v5.9.1
v5.9.2
v6.*
v6.0.0
v6.0.1
v6.1.0
v6.2.0
v6.2.1
v6.3.0
v6.3.1
v6.3.2
v6.4.1
v6.4.2
v6.4.3
v6.4.4
v6.4.5
v6.4.6
v6.5.0
v6.6.0
v6.6.1
v6.6.2
v6.6.3
v6.7.0
v6.7.1
v6.7.2
v6.8.0
v7.*
v7.0.0
v7.1.0
v7.2.0
v7.2.1
v7.2.2
v7.2.3
v7.3.0
v7.4.0
v7.5.0
v7.5.2
v7.5.3
v7.5.4
v7.5.5
v7.5.6
v7.6.0
v7.6.1
v7.6.2
v7.6.3
v7.7.0
v7.7.1
v7.7.2
v7.7.3
v7.7.4
v7.7.5
v7.7.6
v7.7.7
v7.7.8
v7.8.0
v7.8.1
v7.9.0
v9.*
v9.0.0
v9.0.1
v9.0.10
v9.0.2
v9.0.3
v9.0.4
v9.0.5
v9.0.6
v9.0.7
v9.0.8
v9.1.0
v9.2.0
v9.2.1
v9.2.2
v9.2.3
v9.20.4
v9.20.5
v9.20.6
v9.20.7
v9.21.0
v9.21.1
v9.21.2
v9.21.3
v9.21.4
v9.21.5
v9.21.6
v9.22.0
v9.22.1
v9.22.2
v9.22.3
v9.22.4
v9.23.0
v9.23.1
v9.24.0
v9.24.1
v9.24.2
v9.24.3
v9.24.4
v9.24.5
v9.24.6
v9.24.7
v9.24.8
v9.25.0
v9.26.0
v9.26.1
v9.26.2
v9.26.3
v9.27.0
v9.27.1
v9.27.2
v9.27.3
v9.27.4
v9.27.5
v9.27.6
v9.28.0
v9.29.0
v9.29.1
v9.29.2
v9.3.0
v9.30.0
v9.31.0
v9.32.0
v9.32.1
v9.32.2
v9.32.3
v9.33.0
v9.33.1
v9.34.0
v9.34.1
v9.34.2
v9.35.0
v9.35.1
v9.36.0
v9.36.1
v9.37.0
v9.37.1
v9.37.2
v9.37.3
v9.38.0
v9.38.1
v9.38.2
v9.38.3
v9.38.4
v9.38.5
v9.38.6
v9.38.7
v9.38.8
v9.38.9
v9.39.0
v9.39.1
v9.4.0
v9.4.1
v9.5.0
v9.6.0
v9.7.10
v9.7.11
v9.7.12
v9.7.13
v9.7.14
v9.7.15
v9.7.16
v9.7.17
v9.7.18
v9.7.19
v9.7.20
v9.7.4
v9.7.5
v9.7.6
v9.7.7
v9.7.8
v9.7.9
v9.8.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-72912.json"