CVE-2026-72912: CyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaustion when parsing a malformed #recipe= URL

Published Aug 10, 2026
·
Updated

CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CPU when a malformed #recipe= URL fragment containing a large number of unmatched quote characters reaches Utils.parseRecipeConfig(). The function synchronously applies a complex global regular expression that may perform heavy backtracking before rejecting the input, causing the victim's browser tab to freeze during startup for seconds or longer. No code execution, data exfiltration, or privilege escalation occurs. This issue is fixed in version 11.3.0.

Affected Software

1 affected component
CyberChef<11.3.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade CyberChef (pretty-recipe parser / Utils.parseRecipeConfig in src/core/Utils.mjs) to a version that resolves this vulnerability.

    Fixed in 11.3.0

Event History

Aug 10, 2026
CVE Published
via MITRE·09:02 PM
Data Sourced
via MITRE·09:02 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-72912?

CVE-2026-72912 has a medium severity rating of 4.3.

2

How do I fix CVE-2026-72912?

To fix CVE-2026-72912, upgrade to CyberChef version 11.3.0 or later.

3

What type of vulnerability is CVE-2026-72912?

CVE-2026-72912 is a client-side ReDoS vulnerability that can cause CPU exhaustion.

4

What impact does CVE-2026-72912 have on CyberChef users?

CVE-2026-72912 can lead to performance issues on clients' machines when parsing malformed #recipe= URLs.

5

Is CVE-2026-72912 related to any specific component of CyberChef?

CVE-2026-72912 affects the pretty-recipe parser component in the CyberChef application.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203