HIGH · 7.5

CVE-2021-36773

uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursi...

Vulnerability Description

uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality).

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
ScirubyNmatrix< 4.4.9
UblockoriginUblock Origin< 1.36.2
Umatrix ProjectUmatrix< 1.4.2
DebianDebian Linux9.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-36773?

CVE-2021-36773 is a vulnerability with a CVSS score of 7.5 (HIGH). uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursi...

How severe is CVE-2021-36773?

CVE-2021-36773 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-36773?

Check the references section above for vendor advisories and patch information. Affected products include: Sciruby Nmatrix, Ublockorigin Ublock Origin, Umatrix Project Umatrix, Debian Debian Linux.