{"id":"CVE-2026-44658","summary":"Zen Browser: RSS Live-Folder Item URLs Are Not Scheme-Restricted Before Trusted Tab Creation","details":"Zen is a firefox-based browser. Prior to 1.19.12b, RSS feed URLs entered by the user are validated to http: or https: in promptForFeedUrl, but item links inside the feed are not subject to the same restriction. The provider maps each RSS/Atom item link into item.url, filters only for presence and date, and returns the item list. The live-folder manager later creates pinned lazy tabs from these values with gBrowser.addTrustedTab(item.url, ...). This vulnerability is fixed in 1.19.12b.","aliases":["GHSA-cc9c-mmmf-c5j6"],"modified":"2026-08-12T03:51:29.952530517Z","published":"2026-05-11T17:00:31.639Z","database_specific":{"cwe_ids":["CWE-20"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44658.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44658.json"},{"type":"ADVISORY","url":"https://github.com/zen-browser/desktop/security/advisories/GHSA-cc9c-mmmf-c5j6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44658"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zen-browser/desktop","events":[{"introduced":"0"},{"fixed":"cfd1e7a6aa3c06f8d4b049b6a0e2b922b5ab5ad0"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.19.12b"}],"source":"AFFECTED_FIELD"}}],"versions":["1.19.11b","1.19.10b","1.19.9b","1.19.8b","1.19.7b","1.19.6b","1.19.5b","1.19.4b","1.19.3b","1.19.2b","1.19.1b","1.19b","1.18.10b","twilight-1","1.18.9b","1.18.7b","1.18.6b","1.18.5b","1.18.4b","1.18.3b","1.18.2b","1.18.1b","1.18b","1.17.15b","1.17.14b","1.17.13b","1.17.12b","1.17.11b","1.17.10b","1.17.9b","1.17.8b","1.17.7b","1.17.6b","1.17.5b","1.17.3b","1.17.2b","1.17.1b","1.16.4b","1.16.3b","1.16.1b","1.16b","1.15.5b","1.15.4b","1.15.3b","1.15.2b","1.14.11b","1.14.10b","1.14.9b","1.14.8b","1.14.6b","1.14.5b","1.14.4b","1.14.3b","1.14.2b","1.14.1b","1.14b","1.13.2b","1.13.1b","1.13b","1.12.10b","1.12.9b","1.12.8b","1.12.7b","1.12.6b","1.12.5b","1.12.4b","1.12.3b","1.12.2b","1.12b","1.11.5b","1.11.4b","1.11.1b","1.11b","1.10.3b","1.10b","1.9b","1.8.2b","1.8.1b","1.8b","1.7.6b","1.7.4b","1.7.3b","1.7.2b","1.7.1b","1.7b","1.6b","1.0.2-b.5","1.0.2-b.4","1.0.2-b.3","1.0.2-b.2","1.0.2-b.1","1.0.2-b.0","1.0.1-a.19","1.0.1-a.21","1.0.1-a.20","1.0.1-a.18","1.0.1-a.17","1.0.1-a.16","1.0.1-a.15","1.0.1-a.14","1.0.1-a.13","1.0.1-a.12","1.0.1-a.11","1.0.1-a.10","1.0.1-a.9","1.0.1-a.8","1.0.1-a.7","1.0.1-a.6","1.0.1-a.5","1.0.1-a.4","1.0.1-a.3","1.0.1-a.2","1.0.1-a.1","1.0.0-a.39","1.0.0-a.35","1.0.0-a.34","1.0.0-a.33","1.0.0-a.32","1.0.0-a.31","1.0.0-a.30","1.0.0-a.29","1.0.0-a.27","1.0.0-a.26","1.0.0-a.24","1.0.0-a.23","1.0.0-a.16","1.0.0-a.15","1.0.0-a.14","1.0.0-a.13","1.0.0-a.12","1.0.0-a.11","1.0.0-a.10","1.0.0-a.9","1.0.0-a.8","1.0.0-a.7","1.0.0-a.6","1.0.0-a.5","1.0.0-a.4","1.0.0-a.3","1.0.0-a.2","1.0.0-a.1","0.0.0-a.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44658.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"}]}