A vulnerability was found in GCHQ CyberChef up to 11.2.x. It has been declared as problematic. This vulnerability affects the function Utils.parseRecipeConfig of the file src/core/Utils.mjs of the component Pretty-Recipe Parser. The manipulation results in resource consumption.

This vulnerability was named CVE-2026-72912. The attack may be performed from remote. There is no available exploit.

It is recommended to upgrade the affected component.