CVE-2026-8950
Description
Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A same-origin policy bypass in the Networking: HTTP component could allow cross-origin data access.
Vulnerability
CVE-2026-8950 is a same-origin policy bypass in the Networking: HTTP component of Mozilla Firefox, Firefox ESR, and Thunderbird. This vulnerability is present in Firefox versions before 151, Firefox ESR versions before 140.11, Thunderbird versions before 151, and Thunderbird versions before 140.11 [1][2][3][4]. The exact mechanism is not detailed in the available references, but it involves the HTTP component's handling of cross-origin requests [1].
Exploitation
An attacker would need to convince a user to visit a malicious website [2]. The attack can be performed in a browser context; in Thunderbird, scripting is disabled when reading email, so exploitation via email is not feasible [2][3]. The specific conditions required to trigger the bypass are not publicly described [1].
Impact
A successful exploitation of this same-origin policy bypass could allow an attacker to read data from a different origin, leading to information disclosure. The impact is rated as moderate in the respective security advisories [1][2][3][4].
Mitigation
This vulnerability is fixed in Firefox 151 [1], Firefox ESR 140.11 [4], Thunderbird 151 [2], and Thunderbird 140.11 [3], all released on May 19, 2026. Users should update to these versions or later. No workarounds have been disclosed [1].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Range: <151
- Range: <140.11
- Range: <151
- Range: <151
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.mozilla.org/security/advisories/mfsa2026-46/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2026-48/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2026-50/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2026-51/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdPermissions Required
News mentions
0No linked articles in our index yet.