CVE-2026-8945
📛 CVE Title
Sandbox escape in Firefox and Firefox Focus for Android
Description
Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- mozilla
- CVSS severity
- high
- CVSS score
- 7.5 / 10
- CVSS vector
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H- Effective score
- 7.5 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- 2026-05-19
- Published
- 2026-05-19 12:29 UTC
- Last updated
- 2026-05-19 15:12 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/8xxx/CVE-2026-8945.json
- Linked Threat
- CVE-2026-8945 — CVE-2026-8945
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-05-19 14:16:50 UTC
- NVD last modified
- 2026-05-21 20:56:23 UTC
- NVD CVSS v3.1
- 7.5 / 10 HIGH source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
- NVD CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H- Exploitability subscore
- 1.6 / 10
- Impact subscore
- 5.9 / 10
- EPSS score
- 0.0005 (probability of exploitation in next 30 days)
- EPSS percentile
- 17.04% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24
NVD-assigned CWE(s):
CWE-693
(differs from the CNA list above)
NVD / KEV / EPSS data refreshed 2026-05-25 00:34 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-30897 - Assigner
- mozilla
- Published
- May 19, 2026, 12:29:34 PM
- Updated
- May 26, 2026, 5:47:40 PM
- EUVD base score (CVSS 3.1)
-
7.5 / 10
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H - EUVD-reported EPSS
- 0.0600
- Aliases
-
GHSA-jvw5-v42q-rpwc
ENISA description: Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mozilla | Firefox |
151 (unaffected)
|
— |
Affected products — CPE 2.3 (2) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*cpe:2.3:a:mozilla:firefox_focus:*:*:*:*:*:android:*:*
Vendor references (2)
References embedded in the original CVE record by the assigning CNA.
Web references (9)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- http://cwe.mitre.org/data/definitions/693.html rapid7:cwe.mitre.org
- https://attackerkb.com/topics/CVE-2026-8945 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30897 rapid7:euvd.enisa.europa.eu
- http://www.mozilla.org/security/announce/2026/mfsa2026-46.html rapid7:www.mozilla.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-8945 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-8945 tenable:www.cve.org
- https://www.first.org/epss/ tenable:www.first.org
- https://bugzilla.mozilla.org/show_bug.cgi?id=2003171 tenable:bugzilla.mozilla.org
- https://www.mozilla.org/security/advisories/mfsa2026-46/ tenable:www.mozilla.org
NVD-tagged references (2)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://bugzilla.mozilla.org/show_bug.cgi?id=2003171 security@mozilla.org Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2026-46/ security@mozilla.org Vendor Advisory
Remediations (16)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:app.opencve.io
Remediation No vendor fix or workaround currently provided. OpenCVE Recommended Actions Upgrade to Firefox 151 or newer, which contains the fixed sandbox implementation. Upgrade Firefox Focus on Android to the latest release available through the Play Store.
2026-05-23 22:18 UTC -
web:community.broadcom.com
A critical security issue, dubbed NGINX Rift and identified as CVE - 2026 -42945, has been disclosed. This vulnerability affects both NGINX Open Source and NGINX Plus. We are publishing this post to provide immediate guidance and confirm the rapid release of patched images for all affected Bitnami customers. Understanding the Critical Flaw: NGINX Rift ( CVE - 2026 -42945) The NGINX Rift vulnerability ...
2026-05-23 22:18 UTC -
web:guide.sonatype.com
Technical security analysis for CVE-2026-8945 . CVSS 7.5 severity. View CVSS vectors, CWE classifications, and exploit maturity ratings.
2026-05-23 22:18 UTC -
web:hostcay.com
A critical vulnerability in NGINX has moved from theoretical to operational threat within days of disclosure. CVE - 2026 -42945, a heap buffer overflow in the rewrite module, carries a CVSS score of 9.2 and is being actively weaponised in the wild. For operators running NGINX at scale—particularly those managing shared hosting, VPS platforms, or dedicated server infrastructure—this represents ...
2026-05-23 22:18 UTC -
web:nvd.nist.gov
An official website of the United States government Here's how you know
2026-05-23 22:18 UTC -
web:orca.security
A critical vulnerability ( CVE - 2026 -42945, CVSS 9.2) was disclosed affecting NGINX Open Source and NGINX Plus, allowing attackers to reliably trigger denial-of-service (DoS) conditions and potentially achieve remote code execution (RCE) via specially crafted HTTP requests. Due to the potential for widespread disruption across internet-facing applications and ingress infrastructure, immediate ...
2026-05-23 22:18 UTC -
web:socprime.com
CVE - 2026 -42945 Mitigation The priority for CVE - 2026 -42945 mitigation is to upgrade to a fixed release. For NGINX Open Source, that means moving to 1.30.1 or 1.31.0. For NGINX Plus, the fixes were introduced in R32 P6 and R36 P4. Depthfirst also recommends restarting NGINX after the upgrade so worker processes reload the patched binary.
2026-05-23 22:18 UTC -
web:www.fosslinux.com
I break down the critical NGINX Rift vulnerability ( CVE - 2026 -42945) affecting the rewrite module on Linux. Learn how to recursively audit your server configuration files for vulnerable rewrite patterns, implement immediate configuration mitigations using PCRE named capture groups, and successfully upgrade your active NGINX packages to the secure version 1.30.1 today.
2026-05-23 22:18 UTC -
web:www.imperva.com
TL;DR: Researchers recently disclosed CVE - 2026 -42945, a critical heap-based buffer overflow vulnerability affecting both NGINX Open Source and NGINX Plus. The flaw exists within the ngx_http_rewrite_module component and can allow unauthenticated attackers to trigger denial-of-service conditions and potentially achieve remote code execution (RCE) using specially crafted HTTP requests. Imperva ...
2026-05-23 22:18 UTC -
web:www.thehackerwire.com
CVE-2026-8945 is a High severity vulnerability (CVSS 7.5). Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.
2026-05-23 22:18 UTC -
web:dailysecurityreview.com
A critical heap buffer overflow hiding in NGINX's rewrite module for 18 years was publicly disclosed Wednesday, with security researcher "depthfirst" releasing full details of CVE - 2026 -42945 — a CVSS 9.2 flaw that allows unauthenticated remote code execution on servers running with ASLR disabled and reliable denial of service against any affected configuration. NGINX patched the ...
2026-05-26 02:58 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-26 02:58 UTC -
web:securitricks.com
CVE CVE-2026-8945 - Score : 7.5 - Source : security@mozilla.org - Description : Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.
2026-05-26 02:58 UTC -
web:securityboulevard.com
Overview Recently, NSFOCUS CERT detected that Nginx and F5 issued security bulletins to fix the Nginx remote code execution vulnerability ( CVE - 2026 -42945); because the ngx_http_rewrite_module module contains question marks in processing (? ) has a defect in the calculation logic when replacing strings with rewrite. Under certain configuration conditions, an unauthenticated attacker can trigger ...
2026-05-26 02:58 UTC -
web:www.cisecurity.org
Multiple vulnerabilities have been discovered in NGINX, the most severe of which could allow for remote code execution. NGINX is a software used for web serving, reverse proxying, caching, and load balancing. Successful exploitation of the most severe of these vulnerabilities may allow an unauthenticated threat actor to crash vulnerable NGINX worker processes by sending crafted HTTP requests ...
2026-05-26 02:58 UTC -
web:www.mozilla.org
# CVE - 2026 -8969: Mitigation bypass in the DOM: Security component Reporter Atsushi Sada Impact low References Bug 2031123 # CVE - 2026 -8970: Privilege escalation in the Security component Reporter pakhunov.anton.n Impact low References Bug 2032174 # CVE - 2026 -8971: Same-origin policy bypass in the Networking: JAR component Reporter Surya Dev Singh ...
2026-05-26 02:58 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-8945.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2026-8945",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-05-19T15:11:15.996310Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-693",
"description": "CWE-693 Protection Mechanism Failure",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-05-19T15:12:07.561Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Firefox",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "151",
"versionType": "rpm"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "Daisuke Hatakeyama"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151."
}
],
"value": "Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-19T12:29:34.775Z",
"orgId": "f16b083a-5664-49f3-a51e-8d479e5ed7fe",
"shortName": "mozilla"
},
"references": [
{
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2003171"
},
{
"url": "https://www.mozilla.org/security/advisories/mfsa2026-46/"
}
],
"title": "Sandbox escape in Firefox and Firefox Focus for Android"
}
},
"cveMetadata": {
"assignerOrgId": "f16b083a-5664-49f3-a51e-8d479e5ed7fe",
"assignerShortName": "mozilla",
"cveId": "CVE-2026-8945",
"datePublished": "2026-05-19T12:29:34.775Z",
"dateReserved": "2026-05-19T12:29:34.019Z",
"dateUpdated": "2026-05-19T15:12:07.561Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}