Description
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the DOM networking component allows a bypass of the standard mitigation that normally protects web content. The vulnerability can be leveraged by an attacker to override security checks, potentially enabling the execution of malicious code or other actions that would ordinarily be blocked. The weakness corresponds to CWE‑693 (Security Misconfiguration) and CWE‑807 (Use of Exception to Control Flow) and is represented by a CVSS score of 9.8, indicating a critical threat to confidentiality, integrity, and availability.

Affected Systems

Mozilla Firefox and Thunderbird are affected. Any release prior to Firefox 153, Firefox ESR 140.13, Thunderbird 153, or Thunderbird ESR 140.13 contains the flaw, so users running those older versions must update.

Risk and Exploitability

The high CVSS score reflects the ability to bypass fundamental mitigations, but the EPSS score of less than 1 % suggests that, as of now, exploitation likelihood is very low. The vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve malicious web content or extensions that manipulate the DOM within the networking component.

Generated by OpenCVE AI on August 3, 2026 at 00:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to version 153 or later, or the ESR 140.13 release that includes the fix.
  • Upgrade Mozilla Thunderbird to version 153 or later, or the ESR 140.13 release that includes the fix.
  • After the update, review any third‑party extensions or plugins that interact with the networking component and ensure they are current or disable them until updates are available.

Generated by OpenCVE AI on August 3, 2026 at 00:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4695-1 firefox-esr security update
Debian DLA Debian DLA DLA-4727-1 thunderbird security update
Debian DSA Debian DSA DSA-6394-1 firefox-esr security update
Debian DSA Debian DSA DSA-6418-1 thunderbird security update
History

Fri, 24 Jul 2026 00:30:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
References

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
Title Mitigation bypass in the DOM: Networking component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:18:46.699Z

Reserved: 2026-07-20T21:56:56.113Z

Link: CVE-2026-16383

cve-icon Vulnrichment

Updated: 2026-07-22T17:59:07.488Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T13:17:13.460

Modified: 2026-07-24T15:19:09.003

Link: CVE-2026-16383

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T12:37:58Z

Links: CVE-2026-16383 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:00:04Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure

  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision