{"id":"CVE-2020-26955","title":"When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in privat…","summary":"When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in privat…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","cwe":["CWE-565"],"vendor":"mozilla","product":"firefox_mobile","affected":["firefox_mobile < 83.0"],"patched":["firefox_mobile 83.0"],"published":"2020-12-09","updated":"2026-08-19","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-26955","references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1663261","label":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2020-50/","label":"security@mozilla.org"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1663261","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.mozilla.org/security/advisories/mfsa2020-50/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00826,"epssPercentile":0.55918,"ingestedAt":"2026-08-19T15:41:15.012Z","slug":"CVE-2020-26955","body":"## Overview\n\nWhen a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.\n\n## Affected\n\n- `firefox_mobile < 83.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `firefox_mobile 83.0`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}