CVE-2020-26961
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-26961 is a security vulnerability discovered in Firefox's DNS over HTTPS (DoH) implementation that affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5. The vulnerability was reported by Gabriel Corona and disclosed on November 17, 2020. The issue occurs when DoH is in use, where Firefox intentionally filters RFC1918 and related IP ranges from responses, but IPv4 addresses mapped through IPv6 were erroneously allowed through (Mozilla Advisory).

Technical details

The vulnerability stems from an implementation flaw in Firefox's DoH filtering mechanism. When DNS over HTTPS is enabled, Firefox is designed to filter private IP addresses (RFC1918 ranges) from DNS responses as these addresses should not come from a DoH resolver. However, the filtering mechanism failed to identify and block IPv4 addresses when they were mapped through IPv6 format (e.g., ::ffff:192.168.1.254). The vulnerability was assigned a CVSS v3.1 base score of 6.5 (Medium) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N (NVD).

Impact

The vulnerability could lead to potential DNS Rebinding attacks, allowing malicious actors to bypass Firefox's built-in protection against accessing private network resources through DoH. This could potentially expose internal network services to unauthorized access from external websites (Mozilla Advisory, Red Hat).

Exploitability

The vulnerability can be exploited by creating DNS records that return IPv4-mapped IPv6 addresses pointing to private network ranges. When a user visits a malicious website using Firefox with DoH enabled, the attacker could bypass the RFC1918 filtering protection and potentially conduct DNS rebinding attacks against internal network resources (Mozilla Bug).

Mitigation and workarounds

The vulnerability was fixed in Firefox 83, Firefox ESR 78.5, and Thunderbird 78.5. Users should upgrade to these versions or newer to receive the security fix. The patch ensures that IPv4-mapped IPv6 addresses are properly checked against the RFC1918 ranges when using DoH (Mozilla Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management