CVE-2026-72912 is a vulnerability in CyberChef, a web application for encryption, encoding, compression, and data analysis. The vulnerability is caused by a complex regular expression in the pretty-recipe parser that can exhaust client-side CPU when a malformed #recipe= URL fragment is encountered. This can cause the victim's browser tab to freeze during startup for seconds or longer. The issue is fixed i [truncated]
CVE-2026-57439 is a medium-severity vulnerability in CyberChef, a web app for encryption, encoding, compression, and data analysis. The Series Chart operation's acceptance of __proto__ as a key while parsing user-supplied CSV allows for prototype pollution. This issue can be chained with operations such as Parse UDP to inject malicious JavaScript into HTML output. The vulnerability is fixed in version 11. [truncated]