← Back

Geckodriver

geckodriver

Vendor: Mozilla • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mozilla
1Geckodriver
Jun 17, 2026
May 2, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Improved Host header checks to reject requests not sent to a well-known local hostname or IP, or the server-specified hostname.
1Mozilla
1Geckodriver
Jun 17, 2026
Jul 20, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically prepared request, lead to remote code execution.