CVE-2020-26961: Medium severity thunderbird vulnerability
When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver. However when an IPv4 address was mapped through IPv6, these addresses were erroneously let through, leading to a potential DNS Rebinding attack.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-26961?
CVE-2020-26961 is a vulnerability related to DNS over HTTPS (DoH) in Mozilla products, including Firefox ESR, Thunderbird, and Firefox.
What is the severity of CVE-2020-26961?
CVE-2020-26961 has a severity rating of 6.5 (Medium).
Which software versions are affected by CVE-2020-26961?
Mozilla Firefox ESR versions up to and excluding 78.5, Mozilla Thunderbird versions up to and excluding 78.5, and Mozilla Firefox versions up to and excluding 83.0 are affected by CVE-2020-26961.
How does CVE-2020-26961 impact DNS over HTTPS (DoH)?
CVE-2020-26961 allows IPv4 addresses mapped through IPv6 to bypass the intentional filtering of RFC1918 and related IP ranges in DoH, potentially leading to a DNS Rebinding attack.
How can I fix CVE-2020-26961?
To fix CVE-2020-26961, update your Mozilla Firefox ESR to version 78.5 and Thunderbird to version 78.5, or update Mozilla Firefox to version 83.0 or newer.