Home

Description

Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES encryption. MD5 has been broken since 2004 and a single iteration provides no key stretching.

PUBLISHED Reserved 2026-05-18 | Published 2026-06-03 | Updated 2026-06-04 | Assigner certcc

Problem types

CWE-916 Use of Password Hash With Insufficient Computational Effort

Product status

Any version
affected

References

kb.cert.org/vuls/id/595768

cve.org (CVE-2026-8881)

nvd.nist.gov (CVE-2026-8881)

Download JSON