PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72912 gchq CVE debrief

CVE-2026-72912 is a vulnerability in CyberChef, a web application for encryption, encoding, compression, and data analysis. The vulnerability is caused by a complex regular expression in the pretty-recipe parser that can exhaust client-side CPU when a malformed #recipe= URL fragment is encountered. This can cause the victim's browser tab to freeze during startup for seconds or longer. The issue is fixed in version 11.3.0.

Vendor
gchq
Product
CyberChef
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-09-09
Advisory published
2026-08-10
Advisory updated
2026-09-09

Who should care

Defenders who use CyberChef should verify if their instances are vulnerable and upgrade to version 11.3.0 if necessary. Defenders should care about CVE-2026-72912 because it can cause denial of service and impact user experience and productivity in CyberChef instances. Defenders should prioritize verifying if their CyberChef instances are vulnerable and upgrading to version 11.3.0 if necessary.

Why it matters

Defenders should care about CVE-2026-72912 because it can cause denial of service and impact user experience and productivity in CyberChef instances.

  • Denial of service due to browser tab freezing
  • Potential impact on user experience and productivity

Technical summary

The vulnerability is caused by a complex regular expression in the pretty-recipe parser that can exhaust client-side CPU when a malformed #recipe= URL fragment is encountered, causing the victim's browser tab to freeze during startup for seconds or longer. No code execution, data exfiltration, or privilege escalation occurs. The issue is fixed in version 11.3.0. Defenders should prioritize verifying if their CyberChef instances are vulnerable and upgrading to version 11.3.0 if necessary. This issue can cause denial of service and impact user experience and productivity in CyberChef instances.

Defensive priority

Defenders should prioritize verifying if their CyberChef instances are vulnerable and upgrading to version 11.3.0 if necessary.

Recommended defensive actions

  • Verify if the CyberChef instance is vulnerable
  • Upgrade to version 11.3.0 if necessary
  • Monitor for similar vulnerabilities in CyberChef
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is caused by a complex regular expression in the pretty-recipe parser. The issue is fixed in version 11.3.0. Defenders should verify if their instances are vulnerable and review the official advisory for affected scope, severity, and vendor guidance. The CVE record was published on 2026-08-10T21:17:26.130Z and has not been modified since then. No code execution, data exfiltration, or privilege escalation occurs. This issue can cause denial of service and impact user experience and productivity in CyberChef instances.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72912 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72912

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72912 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72912

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.