CVE-2020-26951: Mozilla Firefox

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

Affected products

  • Mozilla Firefox: before 83.0 (fixed in 83.0)
  • Mozilla Firefox ESR: before 78.5 (fixed in 78.5)
  • Mozilla Thunderbird: before 78.5 (fixed in 78.5)

Published 2020-12-09. Last modified 2026-06-17.