CVE-2020-26958: XSS
Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass.
Other sources
Thunderbird did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-26958.
What is the severity of CVE-2020-26958?
The severity of CVE-2020-26958 is medium (4 on a scale of 1-10).
Which software is affected by CVE-2020-26958?
The software affected by CVE-2020-26958 includes Mozilla Firefox ESR version up to 78.5, Mozilla Firefox version up to 83, and Mozilla Thunderbird up to version 78.5.
What is the possible impact of CVE-2020-26958?
CVE-2020-26958 could lead to a cross-site script inclusion vulnerability or a Content Security Policy bypass.
How can I fix CVE-2020-26958?
To fix CVE-2020-26958, update Mozilla Firefox ESR to version 78.5 or later, update Mozilla Firefox to version 83 or later, and update Mozilla Thunderbird to version 78.5 or later.