Junglewise Threat Intelligence

CVE-2026-8950: Mozilla Firefox Same-origin policy bypass in Networking HTTP component

CVE-2026-8950 · Severity: info · Published 2026-05-19

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A security vulnerability has been identified in the Mozilla Firefox web browser's networking component. This flaw allows a malicious website to bypass the 'Same-Origin Policy,' which is a fundamental security feature that prevents websites from interacting with data from other sites. If exploited, an attacker could potentially access sensitive information or perform unauthorized actions on behalf of a user on different websites.

Technical details

A vulnerability in the Networking: HTTP component of Mozilla Firefox allows for a Same-Origin Policy (SOP) bypass. The SOP is a critical security mechanism that restricts how a document or script loaded from one origin can interact with a resource from another origin. By bypassing this policy, a malicious actor could potentially read sensitive data from other domains or perform unauthorized cross-site requests. The vulnerability is addressed in Firefox 151 and Firefox ESR 140.11. Specific root cause details are restricted in the associated Bugzilla report (Bug 1965430), but the flaw is categorized as having 'moderate' impact.

Affected products

  • Mozilla Firefox < 151
  • Mozilla Firefox ESR < 140.11

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: advisory
  • 2026-05-19: patched

References

Related threats