Impact
The flaw in the Networking: Cache component allows an attacker to circumvent safeguards that control the caching of web resources, potentially exposing cached data or manipulating request handling. This bypass can lead to confidentiality breaches, integrity violations, or denial‑of‑service conditions if attackers force malformed or repeated cache requests. The weakness is categorized as CWE‑288, pointing to a failure in limiting the impact of a denial‑of‑service attack.
Affected Systems
Mozilla Firefox and Thunderbird are affected in all releases prior to Firefox 148 and Firefox ESR 140.8, and prior to Thunderbird 148 and Thunderbird ESR 140.8, respectively. Versions newer than those contain the patch and are not impacted.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying no public exploits are known. The attack vector is not explicitly provided in the data; it is inferred to be remote, likely involving network traffic that the browser or client processes, such as malicious web content or tailored HTTP requests.
OpenCVE Enrichment
Debian DLA
Debian DSA