UBUNTU-CVE-2026-8706

Source
https://ubuntu.com/security/CVE-2026-8706
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8706.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-8706
Upstream
  • CVE-2026-8706
Published
2026-05-19T16:16:00Z
Modified
2026-05-20T22:03:09Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.

References

Affected packages

Ubuntu:18.04:LTS
mozjs52

Package

Name
mozjs52
Purl
pkg:deb/ubuntu/mozjs52?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

52.*
52.3.1-0ubuntu3
52.3.1-7fakesync1
52.8.1-0ubuntu0.18.04.1
52.9.1-0ubuntu0.18.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libmozjs-52-0",
            "binary_version": "52.9.1-0ubuntu0.18.04.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8706.json"
Ubuntu:20.04:LTS
mozjs68

Package

Name
mozjs68
Purl
pkg:deb/ubuntu/mozjs68?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

68.*
68.5.0-1~fakesync
68.5.0-2~fakesync
68.6.0-1
68.6.0-1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libmozjs-68-0",
            "binary_version": "68.6.0-1ubuntu1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8706.json"
mozjs52

Package

Name
mozjs52
Purl
pkg:deb/ubuntu/mozjs52?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

52.*
52.9.1-1build1
52.9.1-1ubuntu3

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libmozjs-52-0",
            "binary_version": "52.9.1-1ubuntu3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8706.json"
Ubuntu:22.04:LTS
mozjs102

Package

Name
mozjs102
Purl
pkg:deb/ubuntu/mozjs102?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

102.*
102.11.0-0ubuntu0.22.04.1
102.12.0-0ubuntu0.22.04.1
102.13.0-0ubuntu0.22.04.1
102.15.1-0ubuntu0.22.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libmozjs-102-0",
            "binary_version": "102.15.1-0ubuntu0.22.04.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8706.json"
mozjs78

Package

Name
mozjs78
Purl
pkg:deb/ubuntu/mozjs78?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

78.*
78.13.0-1
78.15.0-2
78.15.0-4ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libmozjs-78-0",
            "binary_version": "78.15.0-4ubuntu1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8706.json"
mozjs91

Package

Name
mozjs91
Purl
pkg:deb/ubuntu/mozjs91?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

91.*
91.5.1-0ubuntu1
91.6.0-1
91.6.0-2
91.7.0-2
91.10.0-0ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libmozjs-91-0",
            "binary_version": "91.10.0-0ubuntu1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8706.json"
Ubuntu:24.04:LTS
mozjs102

Package

Name
mozjs102
Purl
pkg:deb/ubuntu/mozjs102?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

102.*
102.15.1-1
102.15.1-3ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libmozjs-102-0t64",
            "binary_version": "102.15.1-3ubuntu2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8706.json"
mozjs115

Package

Name
mozjs115
Purl
pkg:deb/ubuntu/mozjs115?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

115.*
115.3.0-0ubuntu1
115.4.0-2
115.5.0-1
115.6.0-1
115.7.0-4
115.8.0-1
115.9.0-1
115.9.0-1build1
115.10.0-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libmozjs-115-0t64",
            "binary_version": "115.10.0-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8706.json"