CVE-2022-46873: Mozilla Firefox

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108.

Affected products

  • Mozilla Firefox: before 108.0 (fixed in 108.0)

Published 2022-12-22. Last modified 2026-06-17.