Description
Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Spoofing
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in Firefox’s Networking: HTTP component and allows a malicious actor to present a forged response or server identity to the browser. The flaw enables the attacker to masquerade as a legitimate web server, potentially intercepting sensitive data or delivering malicious content without the user’s awareness. This type of spoofing directly compromises authentication integrity and can lead to man‑in‑the‑middle attacks or phishing through authentic‑appearing HTTPS connections.

Affected Systems

Mozilla products, specifically Firefox and Firefox ESR, are affected. The issue is fixed in Firefox ESR 153.4 and Firefox 157, meaning any older build is vulnerable.

Risk and Exploitability

The CVSS score is not provided, and the EPSS is not available, so the precise magnitude of risk is unclear from the data. According to the KEV catalog, the vulnerability is not listed, indicating no publicly known exploitation at this time. Nevertheless, the flaw involves network traffic that could be abused by an attacker with network proximity or a compromised DNS entry. The attack vector is likely remote over HTTP/HTTPS, though exact exploitation steps are not detailed in the available information.

Generated by OpenCVE AI on September 29, 2026 at 16:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Firefox ESR 153.4 or Firefox 157 or newer, which contain the patch for this spoofing issue.
  • If an immediate update is not possible, restrict outgoing network connections to trusted domains or disable untrusted network interfaces to reduce the attack surface.
  • Monitor browser and server logs for unusual HTTP requests or certificate anomalies that could indicate an attempt to exploit spoofing.

Generated by OpenCVE AI on September 29, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Title Spoofing issue in the Networking: HTTP component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T12:36:30.870Z

Reserved: 2026-09-26T19:18:38.463Z

Link: CVE-2026-100822

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:47.503

Modified: 2026-09-29T13:17:47.503

Link: CVE-2026-100822

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T16:30:18Z

Weaknesses
  • CWE-295

    Improper Certificate Validation