CVE-2017-7842: Mozilla Firefox

Medium severity, CVSS 5.3. EPSS: 1.5% chance of exploitation in the next 30 days.

If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" elements instead of one. One of these requests includes the referrer instead of respecting the set policy to not include a referrer on requests. This vulnerability affects Firefox < 57.

Affected products

  • Mozilla Firefox: up to and including 56.0.2

Published 2018-06-11. Last modified 2026-06-17.