GCHQ maintains a small portfolio of specialized security and analysis tools, including Stroom for event processing and CyberChef for cryptographic and data transformation operations. The observed vulnerability signal centers on web-application input-handling issues, particularly cross-site scripting and improper XML entity handling, which recur across these utilities.
The number and severity of CVEs published that impact products developed by Gchq over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000651CRITICAL Stroom version <5.4.5 contains a XML External Entity (XXE) vulnerability in XML Parser that can result in disclosure of confidential data, denial of service, server side request fo | Aug 20, 2018 | 10.0 | 31 | NO | NO |
CVE-2026-42615HIGH GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring. | Apr 29, 2026 | 7.2 | 28 | NO | NO |
CVE-2019-10779MEDIUM All versions of stroom:stroom-app before 5.5.12 and all versions of the 6.0.0 branch before 6.0.25 are affected by Cross-site Scripting. An attacker website is able to load the Str | Jan 28, 2020 | 6.1 | 21 | NO | NO |
CVE-2019-15532MEDIUM CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs. | Aug 26, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gchq.
Media articles that mention a CVE ID that affects a product developed by Gchq — matched by CVE ID, not by vendor name.