Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-11054

17
FAUCET Score

CVE-2020-11054 describes a user interface vulnerability in qutebrowser versions prior to 1.11.1, where the browser incorrectly displayed a green "secure" URL indicator after a user had previously overridden a certificate error for that site. This could create a false sense of security for the user, despite the underlying certificate issue. The vulnerability has a low CVSS score of 3.5, indicating a network-based attack requiring user interaction and low privileges, with a potential impact of information disclosure. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.11.1CPE matchmatch criteria
cpe:2.3:a:qutebrowser:qutebrowser:*:*:*:*:*:*:*:*
31CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
32CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.5LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.1
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.51%
Probability of exploitation in next 30 days
EPSS Percentile
71.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0151 is in the 99th percentile among its peer group of 404 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: qutebrowserFixed in: 1.11.1

Vendor Advisories (1)

pipGHSA-4rcq-jv2f-898jlow

Incorrect Provision of Specified Functionality in qutebrowser

May 8, 2020

References

bugs.kde.org / show_bug.cgi
Issue TrackingPatchThird Party Advisory
github.com / qutebrowser/qutebrowser/commit/021ab572a319ca3db5907a33a59774f502b3b975
PatchThird Party Advisory
github.com / qutebrowser/qutebrowser/commit/19f01bb42d02da539446a52a25bb0c1232b86327
PatchThird Party Advisory
github.com / qutebrowser/qutebrowser/commit/1b7946ed14b386a24db050f2d6dba81ba6518755
PatchThird Party Advisory
github.com / qutebrowser/qutebrowser/commit/2281a205c3e70ec20f35ec8fafecee0d5c4f3478
PatchThird Party Advisory
github.com / qutebrowser/qutebrowser/commit/4020210b193f77cf1785b21717f6ef7c5de5f0f8
PatchThird Party Advisory
github.com / qutebrowser/qutebrowser/commit/6821c236f9ae23adf21d46ce0d56768ac8d0c467
PatchThird Party Advisory
github.com / qutebrowser/qutebrowser/commit/9bd1cf585fccdfe8318fff7af793730e74a04db3
PatchThird Party Advisory
github.com / qutebrowser/qutebrowser/commit/a45ca9c788f648d10cccce2af41405bf25ee2948
PatchThird Party Advisory
github.com / qutebrowser/qutebrowser/commit/d28ed758d077a5bf19ddac4da468f7224114df23
PatchThird Party Advisory
github.com / qutebrowser/qutebrowser/commit/f5d801251aa5436aff44660c87d7013e29ac5864
PatchThird Party Advisory
github.com / qutebrowser/qutebrowser/issues/5403
Issue TrackingThird Party Advisory
github.com / qutebrowser/qutebrowser/security/advisories/GHSA-4rcq-jv2f-898j
Third Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/7YWJ5QNHXKTGG5NLV7EGEOKPBVZBA5GS
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/MKAZOOTJ2MBHTYVYQQ52NL53F5CB2XAP
tracker.die-offenbachs.homelinux.org / eric/issue328
Broken LinkThird Party Advisory