Closed Bug 2031064 (CVE-2026-8955) Opened 5 months ago Closed 5 months ago

`EventSource` in Web Workers bypasses the `connect-src` CSP directive

Categories

(Core :: DOM: Workers, defect)

defect

Tracking

()

RESOLVED FIXED
151 Branch
Tracking Status
firefox-esr115 --- wontfix
firefox-esr140 151+ fixed
firefox149 --- wontfix
firefox150 --- wontfix
firefox151 + fixed

People

(Reporter: lebr0nli, Assigned: tschuster)

Details

(Keywords: csectype-priv-escalation, reporter-external, sec-moderate, Whiteboard: [client-bounty-form][adv-main151+][adv-esr140.11+])

Attachments

(3 files)

2.01 KB, text/x-python-script
Details
48 bytes, text/x-phabricator-request
Details | Review
48 bytes, text/x-phabricator-request
Details | Review
Attached file server.py —

VULNERABILITY DETAILS

CSP is not properly enforced when instantiating an EventSource within a Web Worker. This allows an attacker to bypass the restrictive connect-src directive and establish connections to arbitrary URLs with EventSource.

VERSION

Firefox Version: 149.0.2 stable

The vulnerability is also present in Firefox 151.0a1 nightly

REPRODUCTION CASE

Steps to reproduce

  1. Run the attached server.py with python3 server.py to start the local server.
  2. Navigate to either http://127.0.0.1:1337/?blob or http://127.0.0.1:1337/?worker.js in the browser. This will trigger the page to spawn a Web Worker using either a Blob URL or the worker.js script.
  3. The worker will attempt to establish an EventSource connection to http://127.0.0.1:1337/bypass?blob or http://127.0.0.1:1337/bypass?worker.js.

Expected results

The connection should be blocked by the connect-src 'none' CSP.

Actual results

The connection is successfully established.

CREDIT INFORMATION

Reporter credit: lebr0nli of National Yang Ming Chiao Tung University, Dept. of CS, Security and Systems Lab.

Flags: sec-bounty?
Group: firefox-core-security → dom-core-security
Component: Security → DOM: Security
Product: Firefox → Core

I believe this is another instance of a channel being created without an appropriate ClientInfo being passed: https://searchfox.org/firefox-main/rev/6925ce3cf2987bec22cae8a32e1e8a57e49efd3b/dom/base/EventSource.cpp#1038-1046

Component: DOM: Security → DOM: Workers
Status: UNCONFIRMED → NEW
Ever confirmed: true
Attached file (secure) —
Assignee: nobody → tschuster
Status: NEW → ASSIGNED
Group: dom-core-security → core-security-release
Status: ASSIGNED → RESOLVED
Closed: 5 months ago
Resolution: --- → FIXED
Target Milestone: --- → 151 Branch

Please nominate this for ESR140 uplift when you have a chance.

Flags: needinfo?(tschuster)

firefox-esr140 Uplift Approval Request

  • User impact if declined/Reason for urgency: A web security feature CSP could be bypassed and unexpected requests could happen.
  • Code covered by automated testing?: no
  • Fix verified in Nightly?: yes
  • Needs manual QE testing?: no
  • Steps to reproduce for manual QE testing:
  • Risk associated with taking this patch: low
  • Explanation of risk level: Simple and the normal tests for EventSource in Worker continue to pass.
  • String changes made/needed?: no
  • Is Android affected?: yes
Attachment #9570994 - Flags: approval-mozilla-esr140?
Attached file (secure) —
Flags: needinfo?(tschuster)
Attachment #9570994 - Flags: approval-mozilla-esr140? → approval-mozilla-esr140+
Flags: sec-bounty? → sec-bounty+
QA Whiteboard: [qa-triage-done-c152/b151][sec]
Whiteboard: [client-bounty-form] → [client-bounty-form][adv-main151+][adv-main151+][adv-esr115.36+][adv-esr115.36+][adv-esr140.11+][adv-esr140.11+]
Whiteboard: [client-bounty-form][adv-main151+][adv-main151+][adv-esr115.36+][adv-esr115.36+][adv-esr140.11+][adv-esr140.11+] → [client-bounty-form][adv-main151+][adv-esr140.11+]
Alias: CVE-2026-8955
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: