CVE-2026-8950
9.3 CRITICALSame-origin policy bypass in the Networking: HTTP component
Published: 2026-05-19 · Last updated: 2026-05-20
Severity and scoring
- CVSS
- 9.3 CRITICAL
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
- CWE
- CWE-346
Affected products
| Vendor | Product |
|---|---|
| mozilla | firefox, thunderbird |
Description
Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-8950
- [Other]https://bugzilla.mozilla.org/show_bug.cgi?id=1965430
- [Vendor advisory]https://www.mozilla.org/security/advisories/mfsa2026-46/
- [Vendor advisory]https://www.mozilla.org/security/advisories/mfsa2026-48/
- [Vendor advisory]https://www.mozilla.org/security/advisories/mfsa2026-50/
- [Vendor advisory]https://www.mozilla.org/security/advisories/mfsa2026-51/
Related CVEs
Same vendor
- CVE-2026-10702 — JIT miscompilation in the JavaScript Engine: JIT component (4.3 MEDIUM)
- CVE-2026-10701 — Incorrect boundary conditions in the Graphics: Text component (7.5 HIGH)
- CVE-2026-9309 — Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata (5.4 MEDIUM)
- CVE-2026-9308 — Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders (5.4 MEDIUM)
- CVE-2026-9078 — Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI ... (5.4 MEDIUM)
Same CWE
- CVE-2026-45173 — Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its...
- CVE-2026-12032 — Inappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromis... (3.1 LOW)
- CVE-2026-41700 — Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking (8.1 HIGH)
- CVE-2026-42558 — Xibo is an open source digital signage platform with a web content management system and Windows display player software (7.6 HIGH)
- CVE-2026-10846 — NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query...