Web Application Vulnerability in CyberChef by GCHQ
CVE-2026-72912

4.3MEDIUM

Key Information:

Vendor

Gchq

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72912?

CyberChef, a web application developed by GCHQ for data processing tasks such as encryption and encoding, exhibits a Denial of Service vulnerability in its pretty-recipe parser. When a malformed URL containing numerous unmatched quotation marks is submitted, the Utils.parseRecipeConfig() function can trigger excessive CPU usage on the client side. This leads to severe performance degradation, where the browser tab may remain unresponsive during startup for extended periods. Importantly, this vulnerability does not involve code execution, data exfiltration, or privilege escalation but can significantly impact user experience. The issue has been resolved in version 11.3.0.

Affected Version(s)

CyberChef < 11.3.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.