uBlock Origin is a widely deployed browser extension for ad blocking and content filtering whose vulnerability surface concentrates on its core product and recurs through input-validation and regular-expression processing flaws, including inefficient regex complexity, uncontrolled recursion, and resource-exhaustion weaknesses characteristic of content-filtering logic. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ublockorigin over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11595CRITICAL In uBlock before 0.9.5.15, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web service loads a script for execution | Apr 29, 2019 | 9.0 | 28 | NO | NO |
CVE-2021-36773HIGH uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of servic | Jul 18, 2021 | 7.5 | 25 | NO | NO |
A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is the function currentStateChanged of the file src/js/1p-filter | May 2, 2025 | 3.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ublockorigin.
Media articles that mention a CVE ID that affects a product developed by Ublockorigin — matched by CVE ID, not by vendor name.