What is CVE-2026-72912?
A vulnerability in CyberChef's recipe parser can exhaust client-side CPU resources via a crafted #recipe= URL fragment containing many unmatched quotes. This affects versions prior to 11.3.0 due to improper handling in Utils.parseRecipe. Users should upgrade immediately to the patched version.
Azərbaycanca: CyberChef veb tətbiqində aşkar edilmiş boşluq, zərərli #recipe= URL fraqmenti vasitəsilə müştəri tərəfində CPU resurslarının tükənməsinə səbəb olur. Bu, Utils.parseRecipe funksiyasında dırnaq işarələrinin düzgün işlənməməsindən qaynaqlanır və 11.3.0 versiyasına qədər təsir edir. İstifadəçilər dərhal son versiyaya yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which versions of CyberChef are affected by CVE-2026-72912?
This vulnerability affects versions of CyberChef prior to 11.3.0.
How can I protect against CVE-2026-72912 in CyberChef?
You should upgrade immediately to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.