Description
Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an information disclosure flaw in Firefox’s Networking: HTTP component. An attacker could read data that should remain confidential, such as personal information or authentication tokens, when the browser processes crafted HTTP traffic. The weakness arises from the component failing to mask sensitive data before exposure. This flaw can lead to privacy violations and may facilitate account takeover if accessed privileged information.

Affected Systems

All Firefox installations before version 155 and the ESR branch before 153.2 are affected. The patch was delivered in Firefox 155 and ESR 153.2. Users on newer releases are not affected.

Risk and Exploitability

No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog, implying that widespread exploitation is not currently documented. The likely attack vector is a malicious web page or a network proxy that manipulates HTTP requests or responses reaching the vulnerable component. Because the flaw requires the victim to use an affected browser and to load content that exercises the code path, the risk to organisations with strict confidentiality requirements remains moderate to high despite the low known exploitation incidence.

Generated by OpenCVE AI on September 1, 2026 at 13:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 155 or newer, or upgrade the ESR branch to 153.2 or newer. This is the only officially supported fix.
  • Enable automatic updates so that future security patches are applied promptly without manual intervention.
  • If an immediate upgrade is not possible, block external HTTP traffic to the client using firewall rules or network segmentation until the upgrade is performed.

Generated by OpenCVE AI on September 1, 2026 at 13:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Title Information disclosure in the Networking: HTTP component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T12:18:58.805Z

Reserved: 2026-09-01T07:25:37.771Z

Link: CVE-2026-84132

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T13:20:07.230

Modified: 2026-09-01T13:20:07.230

Link: CVE-2026-84132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:14:52Z

Weaknesses

No weakness.