Description
Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Published: 2026-09-01
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: DOM navigation manipulation
Action: Patch
AI Analysis

Impact

This vulnerability, titled "Other issue in the DOM: Navigation component", was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. The description indicates an issue in the navigation component’s input handling, which is classified as CWEs 200 and 79. While no explicit exploitation vector is documented, the flaw appears to affect browser navigation behavior, potentially allowing a malicious site to influence the browser’s navigation path and redirect users to unintended or harmful destinations without granting code execution privileges.

Affected Systems

Mozilla Firefox versions before 155 and the Firefox ESR branch below 153.2, along with Mozilla Thunderbird versions before 155 and the Thunderbird ESR branch below 153.2, are affected. All later releases are considered secure as the flaw has been resolved.

Risk and Exploitability

The EPSS score is less than 1%, indicating a low exploit probability, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 9.8, classifying it as critical severity. While no explicit exploitation vector is documented, it is inferred that a malicious web page could exploit the DOM navigation component, leading to navigation manipulation without code execution privileges. The overall risk is limited to browser navigation disruption.

Generated by OpenCVE AI on September 3, 2026 at 21:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to at least version 155 or its ESR 153.2 release, and upgrade Mozilla Thunderbird to at least version 155 or its ESR 153.2 release.
  • If an upgrade cannot be applied immediately, avoid visiting untrusted or unknown web pages that could potentially exploit the navigation component.
  • Maintain browser extensions and plugins up to date to reduce the risk of auxiliary vulnerabilities affecting navigation.

Generated by OpenCVE AI on September 3, 2026 at 21:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601

Thu, 03 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 03 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
Weaknesses CWE-79
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Wed, 02 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601

Wed, 02 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2. Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
References

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Title Other issue in the DOM: Navigation component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-03T17:24:14.797Z

Reserved: 2026-09-01T07:25:46.560Z

Link: CVE-2026-84136

cve-icon Vulnrichment

Updated: 2026-09-03T16:46:55.541Z

cve-icon NVD

Status : Modified

Published: 2026-09-01T13:20:07.700

Modified: 2026-09-03T18:17:25.980

Link: CVE-2026-84136

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T22:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')