CVE Vulnerabilities

CVE-2026-20665

Protection Mechanism Failure

Published: Mar 25, 2026 | Modified: Mar 25, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.4 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

Weakness

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Affected Software

NameVendorStart VersionEnd Version
SafariApple*26.4 (excluding)
IpadosApple*18.7.7 (excluding)
IpadosApple26.0 (including)26.4 (excluding)
Iphone_osApple*18.7.7 (excluding)
Iphone_osApple26.0 (including)26.4 (excluding)
MacosApple*26.4 (excluding)
TvosApple*26.4 (excluding)
VisionosApple*26.4 (excluding)
WatchosApple*26.4 (excluding)
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatwebkitgtk4-0:2.52.3-1.el7_9*
Red Hat Enterprise Linux 8RedHatwebkit2gtk3-0:2.52.3-1.el8_10*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatwebkit2gtk3-0:2.52.3-1.el8_4*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatwebkit2gtk3-0:2.52.3-1.el8_4*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatwebkit2gtk3-0:2.52.3-1.el8_6*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatwebkit2gtk3-0:2.52.3-1.el8_6*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatwebkit2gtk3-0:2.52.3-1.el8_6*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatwebkit2gtk3-0:2.52.3-1.el8_8*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatwebkit2gtk3-0:2.52.3-1.el8_8*
Red Hat Enterprise Linux 9RedHatwebkit2gtk3-0:2.52.3-1.el9_8*
Red Hat Enterprise Linux 9RedHatwebkit2gtk3-0:2.52.3-0.el9_7.1*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatwebkit2gtk3-0:2.52.3-1.el9_0*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatwebkit2gtk3-0:2.52.3-1.el9_2*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatwebkit2gtk3-0:2.52.3-1.el9_4*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatwebkit2gtk3-0:2.52.3-1.el9_6*
Qtwebkit-opensource-srcUbuntuesm-apps/bionic*
Qtwebkit-opensource-srcUbuntuesm-apps/focal*
Qtwebkit-opensource-srcUbuntuesm-apps/jammy*
Qtwebkit-opensource-srcUbuntuesm-apps/noble*
Qtwebkit-opensource-srcUbuntuesm-infra-legacy/xenial*
Qtwebkit-opensource-srcUbuntuesm-infra/xenial*
Qtwebkit-opensource-srcUbuntujammy*
Qtwebkit-opensource-srcUbuntunoble*
Qtwebkit-sourceUbuntuesm-apps-legacy/xenial*
Qtwebkit-sourceUbuntuesm-apps/bionic*
Qtwebkit-sourceUbuntuesm-apps/xenial*
Webkit2gtkUbuntudevel*
Webkit2gtkUbuntuesm-infra-legacy/xenial*
Webkit2gtkUbuntuesm-infra/bionic*
Webkit2gtkUbuntuesm-infra/focal*
Webkit2gtkUbuntuesm-infra/xenial*
Webkit2gtkUbuntujammy*
Webkit2gtkUbuntunoble*
Webkit2gtkUbuntuquesting*
Webkit2gtkUbunturesolute*
Webkit2gtkUbuntuupstream*
WebkitgtkUbuntuesm-apps-legacy/xenial*
WebkitgtkUbuntuesm-apps/bionic*
WebkitgtkUbuntuesm-apps/xenial*
WpewebkitUbuntuesm-apps/focal*
WpewebkitUbuntuesm-apps/jammy*
WpewebkitUbuntujammy*

References