Impact
This CVE describes a flaw in Firefox and Thunderbird’s Networking: HTTP component that allows an attacker to bypass built‑in mitigations. The issue does not specify the exact safeguards that are bypassed, but the description states that mitigations can be circumvented, potentially allowing an attacker to affect the client in ways the original mitigations intended to prevent. The weakness is classified under CWE‑288 and CWE‑444.
Affected Systems
Mozilla Firefox versions older than 149, Firefox ESR older than 140.9, Mozilla Thunderbird versions older than 149, and Thunderbird ESR older than 140.9 are impacted.
Risk and Exploitability
The CVSS score of 9.8 places the vulnerability in the high‑to‑critical range. However, the EPSS score is less than 1%, indicating that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to present the affected client with a malicious web page or email that triggers the HTTP networking component; the likely attack vector is remote network access. Specific exploitation steps are not detailed in the CVE record, so the exact method remains unspecified.
OpenCVE Enrichment
Debian DLA
Debian DSA