Description
Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Information disclosure in the Networking: WebSockets component, as identified by Mozilla. The flaw enables unauthorized parties to read data that should remain confidential, a weakness catalogued as CWE-200. No exploitation prerequisites beyond interacting with the vulnerable WebSocket component are implied, so the attack can potentially be carried out by any entity that can influence WebSocket traffic between the client and a server.

Affected Systems

Mozilla products are affected. Users of Firefox versions prior to 153 and ESR builds prior to 140.13 are vulnerable. Thunderbird users on versions older than 153 or ESR builds older than 140.13 are also impacted. Any installations of these browsers/clients that have not yet received the patch are at risk.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, but the EPSS score of less than 1% shows a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. While the exact attack vector is not specified in the provided information, it is inferred that an attacker would need to interact with the vulnerable WebSocket component, possibly through a malicious website or local application, to gain access to the exposed data.

Generated by OpenCVE AI on August 3, 2026 at 00:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 153 or later, or to the ESR 140.13 release, to eliminate the flaw.
  • Upgrade Thunderbird to version 153 or later, or to the ESR 140.13 release, to address the vulnerability.
  • If an immediate upgrade is not possible, restrict or disable WebSocket usage in the affected applications until the patch can be applied.

Generated by OpenCVE AI on August 3, 2026 at 00:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4695-1 firefox-esr security update
Debian DLA Debian DLA DLA-4727-1 thunderbird security update
Debian DSA Debian DSA DSA-6394-1 firefox-esr security update
Debian DSA Debian DSA DSA-6418-1 thunderbird security update
History

Fri, 24 Jul 2026 00:30:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
References

Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
Title Information disclosure in the Networking: WebSockets component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:19:10.922Z

Reserved: 2026-07-20T21:57:42.043Z

Link: CVE-2026-16405

cve-icon Vulnrichment

Updated: 2026-07-21T19:24:41.997Z

cve-icon NVD

Status : Modified

Published: 2026-07-21T13:17:15.910

Modified: 2026-07-22T20:16:59.350

Link: CVE-2026-16405

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-21T12:38:17Z

Links: CVE-2026-16405 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-201

    Insertion of Sensitive Information Into Sent Data