CVE-2020-12421: Medium severity Mozilla Firefox vulnerability
Last updated 25 August 2025
Other sources
When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-12421?
CVE-2020-12421 is a vulnerability that affects Mozilla Firefox and Thunderbird.
How does CVE-2020-12421 affect add-on updates?
CVE-2020-12421 can cause add-on updates to fail if the certificate chain terminates in non-built-in-roots.
Which versions of Mozilla Firefox are affected by CVE-2020-12421?
Mozilla Firefox versions up to and excluding 78 are affected by CVE-2020-12421.
Which versions of Thunderbird are affected by CVE-2020-12421?
Thunderbird versions up to and excluding 68.10 and 78 are affected by CVE-2020-12421.
What is the severity rating of CVE-2020-12421?
CVE-2020-12421 has a severity rating of medium.
How can I fix the CVE-2020-12421 vulnerability?
Update your Mozilla Firefox or Thunderbird to a version that includes the fix provided by Mozilla.
Where can I find more information about CVE-2020-12421?
You can find more information about CVE-2020-12421 on the Mozilla website: [link].