Impact
The vulnerability is a mitigation bypass in the Networking : HTTP component of Mozilla products. The flaw allows an attacker to evade built‑in HTTP security protections. By injecting specially crafted HTTP traffic, the attacker can undermine the intended security controls. This weakness is described with CWE‑288 and CWE‑444.
Affected Systems
Affected are Firefox versions prior to 149 and prior to ESR 140.9, as well as Thunderbird versions prior to 149 and prior to ESR 140.9. The issue is specific to the HTTP networking subsystem shared by these applications.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score falls below 1 %, so exploitation is unlikely at present. The flaw is not listed in the CISA KEV catalog, suggesting no documented widespread attacks. Likely the attack vector is remote over the network, with an attacker able to craft HTTP requests to a vulnerable client.
OpenCVE Enrichment
Debian DLA
Debian DSA