CVE-2020-12409: Mozilla Firefox

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of an encoded URL. This vulnerability affects Firefox < 77.

Affected products

  • Mozilla Firefox: before 77.0 (fixed in 77.0)

Published 2020-07-09. Last modified 2026-06-17.