CVE-2026-8874

Severity CVSS v4.0:
Pending analysis
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
03/06/2026
Last modified:
22/07/2026

Description

Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP via the Fetch API. Other endpoints in the same extension correctly fetch IWF and CIPA data over HTTPS, demonstrating an inconsistent implementation of TLS.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:securly:securly:3.0.7:*:*:*:*:chrome:*:*


References to Advisories, Solutions, and Tools