Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial of Service when trying to starting new SWS sessions.This issue affects CyberArk Secure Web Sessions Extension: before 2.2.30305.
History

Thu, 27 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Cyberark
Cyberark secure Web Sessions Extension
Vendors & Products Cyberark
Cyberark secure Web Sessions Extension

Thu, 27 Nov 2025 03:00:00 +0000

Type Values Removed Values Added
Description Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial of Service when trying to starting new SWS sessions.This issue affects CyberArk Secure Web Sessions Extension: before 2.2.30305.
Title Client-Side Denial of Service Condition in SWS Extension prior to version 2.2.30305
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:A/AU:Y'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GovTech CSG

Published: 2025-11-27T02:50:03.874Z

Updated: 2025-11-27T06:03:49.612Z

Reserved: 2025-11-27T02:49:11.941Z

Link: CVE-2025-13762

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-27T03:15:58.613

Modified: 2025-11-27T03:15:58.613

Link: CVE-2025-13762

cve-icon Redhat

No data.