CVE-2020-26957
NixOS vulnerability analysis and mitigation

Overview

OneCRL was non-functional in Firefox for Android (Fenix) due to a missing service initialization, tracked as CVE-2020-26957. The vulnerability was discovered in 2020 and affected Firefox for Android versions prior to 83. This security issue was specific to the Android version of Firefox, with other operating systems remaining unaffected (Mozilla Advisory).

Technical details

The vulnerability stemmed from a regression introduced during code reorganization where initialization code was moved from the security module to the browser component without including the corresponding code in mobile implementations. This resulted in OneCRL, Mozilla's certificate revocation mechanism, failing to initialize properly in Firefox for Android. The issue was assigned a CVSS v3.1 base score of 6.5 (Medium) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N (NVD).

Impact

The vulnerability prevented Firefox for Android from enforcing certificate revocations through OneCRL, which is Mozilla's mechanism for addressing compromised or maliciously issued certificates. This could potentially allow connections to websites using revoked certificates, exposing users to security risks from compromised or malicious certificates that should have been blocked (Mozilla Bug).

Exploitability

While there were no reported instances of this vulnerability being exploited in the wild, the impact was considered moderate due to its potential to bypass certificate revocation checks. The vulnerability required no special privileges to exploit, though its impact was limited to certificate revocation enforcement (Mozilla Advisory).

Mitigation and workarounds

The vulnerability was fixed in Firefox for Android version 83 by properly initializing the OneCRL service when GeckoView starts. Users were advised to update to Firefox for Android version 83 or later to receive the security fix (Mozilla Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management