Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial of Service when trying to starting new SWS sessions.This issue affects CyberArk Secure Web Sessions Extension: before 2.2.30305.
Advisories

No advisories yet.

Fixes

Solution

Update SWS extension to v2.2.30305 or newer


Workaround

No workaround given by the vendor.

History

Thu, 27 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Cyberark
Cyberark secure Web Sessions Extension
Vendors & Products Cyberark
Cyberark secure Web Sessions Extension

Thu, 27 Nov 2025 03:00:00 +0000

Type Values Removed Values Added
Description Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial of Service when trying to starting new SWS sessions.This issue affects CyberArk Secure Web Sessions Extension: before 2.2.30305.
Title Client-Side Denial of Service Condition in SWS Extension prior to version 2.2.30305
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:A/AU:Y'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GovTech CSG

Published:

Updated: 2025-11-27T06:03:49.612Z

Reserved: 2025-11-27T02:49:11.941Z

Link: CVE-2025-13762

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-27T03:15:58.613

Modified: 2025-11-27T03:15:58.613

Link: CVE-2025-13762

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-27T16:26:40Z