Firefox Same-origin policy bypass in JAR component before 148/ESR 140.8
CVE-2026-2790 Published on February 24, 2026

Same-origin policy bypass in the Networking: JAR component
Same-origin policy bypass in the Networking: JAR component. This vulnerability affects Firefox < 148 and Firefox ESR < 140.8.

NVD


Products Associated with CVE-2026-2790

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-2790 are published in these products:

 
 

Affected Versions

Mozilla Firefox: Mozilla Firefox ESR: Mozilla Thunderbird: Mozilla Thunderbird: