CVE-2014-1582: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

The Public Key Pinning (PKP) implementation in Mozilla Firefox before 33.0 does not properly consider the connection-coalescing behavior of SPDY and HTTP/2 in the case of a shared IP address, which allows man-in-the-middle attackers to bypass an intended pinning configuration and spoof a web site by providing a valid certificate from an arbitrary recognized Certification Authority.

Affected products

  • Mozilla Firefox: up to and including 32.0; version 30.0 only; version 31.0 only; version 31.1.0 only

Published 2014-10-15. Last modified 2026-06-17.