CVE-2020-12401: Mozilla Firefox

Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

Affected products

  • Mozilla Firefox: before 80.0 (fixed in 80.0)
  • Mozilla Firefox Mobile: before 80.0 (fixed in 80.0)

Published 2020-10-08. Last modified 2026-08-19.