CVE Explorer
CVE-2026-8874
Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP via the Fetch API. Other endpoints in the same extension correctly fetch IWF and CIPA data over HTTPS, demonstrating an inconsistent implementation of TLS.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-319","description":"CWE-319 Cleartext Transmission of Sensitive Information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f906f974661ffda744c86b0d01d0644c089cce26f77f93e3c44731557aa55929 · sha256:fbefd6225610643d… · /containers/adp/0/problemTypes/0/descriptions/0
{"description":"CWE-319 Cleartext Transmission of Sensitive Information","lang":"en"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f906f974661ffda744c86b0d01d0644c089cce26f77f93e3c44731557aa55929 · sha256:fbefd6225610643d… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"Securly Chrome Extension","vendor":"Securly","versions":[{"lessThan":"3.0.7","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f906f974661ffda744c86b0d01d0644c089cce26f77f93e3c44731557aa55929 · sha256:fbefd6225610643d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f906f974661ffda744c86b0d01d0644c089cce26f77f93e3c44731557aa55929 · sha256:fbefd6225610643d… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-319","description":"CWE-319 Cleartext Transmission of Sensitive Information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f906f974661ffda744c86b0d01d0644c089cce26f77f93e3c44731557aa55929 · sha256:fbefd6225610643d… · /containers/adp/0/problemTypes/0/descriptions/0
{"description":"CWE-319 Cleartext Transmission of Sensitive Information","lang":"en"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f906f974661ffda744c86b0d01d0644c089cce26f77f93e3c44731557aa55929 · sha256:fbefd6225610643d… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://kb.cert.org/vuls/id/595768"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f906f974661ffda744c86b0d01d0644c089cce26f77f93e3c44731557aa55929 · sha256:fbefd6225610643d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.