Description
Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability involves a flaw in Firefox’s navigation component that can affect how the browser handles DOM changes. The defect may allow an attacker, via a crafted web page, to manipulate navigation behavior or redirect users to unintended sites.

Affected Systems

Mozilla Firefox versions prior to 155 and the Firefox ESR branch below 153.2 are vulnerable. The issue was fixed in Firefox 155 and Firefox ESR 153.2. All other versions are unaffected.

Risk and Exploitability

EPSS score unavailable and the vulnerability is not listed in the CISA KEV catalog, indicating limited public exploitation data. There is no CVSS score provided, so the severity cannot be quantified here. The likely attack vector is a malicious web page that exploits the DOM navigation component; the exploit would require the victim to visit a crafted site, and the consequence is limited to manipulation of navigation behavior rather than full code execution.

Generated by OpenCVE AI on September 1, 2026 at 13:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 155 or newer, or the Firefox ESR 153.2 or newer release.
  • If an upgrade cannot be applied immediately, avoid visiting untrusted web pages that could exploit the navigation component.
  • Maintain up-to-date browser extensions and plugins to reduce the risk of auxiliary vulnerabilities affecting navigation.

Generated by OpenCVE AI on September 1, 2026 at 13:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Title Other issue in the DOM: Navigation component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T12:19:02.913Z

Reserved: 2026-09-01T07:25:46.560Z

Link: CVE-2026-84136

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T13:20:07.700

Modified: 2026-09-01T13:20:07.700

Link: CVE-2026-84136

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:00:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')