CVE-2026-8971: Same-origin policy bypass in the Networking: JAR component
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151 - Upgrade
Upgrade
Firefox (Networking: JAR)to a version that resolves this vulnerability.Fixed in 151 - Upgrade
Upgrade
Thunderbird (Networking: JAR)to a version that resolves this vulnerability.Fixed in 151
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-8945
- CVE-2026-8946
- CVE-2026-8947
- CVE-2026-8948
- CVE-2026-8949
- CVE-2026-8950
- CVE-2026-8951
- CVE-2026-8952
- CVE-2026-8953
- CVE-2026-8954
- CVE-2026-8955
- CVE-2026-8956
- CVE-2026-8957
- CVE-2026-8958
- CVE-2026-8959
- CVE-2026-8960
- CVE-2026-8961
- CVE-2026-8962
- CVE-2026-8963
- CVE-2026-8964
- CVE-2026-8965
- CVE-2026-8966
- CVE-2026-8967
- CVE-2026-8968
- CVE-2026-8969
- CVE-2026-8970
- CVE-2026-8971
- CVE-2026-8972
- CVE-2026-8973
- CVE-2026-8974
- CVE-2026-8975
Frequently Asked Questions
What is the severity of CVE-2026-8971?
CVE-2026-8971 is classified as a high-severity vulnerability due to its ability to bypass the same-origin policy.
How do I fix CVE-2026-8971?
To fix CVE-2026-8971, update Firefox or Thunderbird to version 151 or later.
What types of software are affected by CVE-2026-8971?
CVE-2026-8971 affects Mozilla Firefox and Mozilla Thunderbird versions prior to 151.
What is the main risk associated with CVE-2026-8971?
The main risk of CVE-2026-8971 is that it allows attackers to bypass security controls intended to prevent cross-origin attacks.
Was CVE-2026-8971 addressed in any software updates?
Yes, CVE-2026-8971 was addressed and fixed in the updates for Firefox and Thunderbird version 151.