Description
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
Published: 2026-05-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is located in Mozilla Firefox’s Security component. It allows an attacker to read sensitive information that resides in the Document Object Model. The exposure could include URLs, user credentials, or other configuration details that normally remain confidential, resulting in an information‑exposure weakness. Based on the description, it is inferred that the attacker may trigger this issue via a malicious web page or script.

Affected Systems

All releases of Mozilla Firefox and Thunderbird prior to version 151 are affected. The issue was rectified in version 151, so any installation older than that release contains the vulnerability.

Risk and Exploitability

The CVSS score is 7.5 and the EPSS score is less than 1%, indicating a moderate to high severity but a low exploitation probability. The description indicates the vulnerability involves information disclosure in the DOM, but does not specify the attack vector. Based on the nature of the flaw, it is inferred that a web‑based attack might trigger the bug. The lack of a KEV listing and absence of widespread exploitation evidence suggest the risk is currently low, but the impact is significant if compromised.

Generated by OpenCVE AI on May 20, 2026 at 18:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch for Mozilla Firefox version 151 or later to eliminate the DOM information disclosure that corresponds to CWE-200.
  • Review and tighten the browser’s privacy settings, ensuring that sensitive data handling follows the least‑privilege principle to mitigate information exposure as identified by CWE-200.
  • Configure a strict content security policy and enable automatic updates to reduce the possibility of malicious scripts exploiting the vulnerability, aligning with CWE-200 mitigation practices.

Generated by OpenCVE AI on May 20, 2026 at 18:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 20 May 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
Vendors & Products Mozilla thunderbird

Wed, 20 May 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 19 May 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 19 May 2026 17:45:00 +0000

Type Values Removed Values Added
Description Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151. Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
References

Tue, 19 May 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 19 May 2026 13:45:00 +0000

Type Values Removed Values Added
Description Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151.
Title Information disclosure in the DOM: Security component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-05-20T15:46:19.647Z

Reserved: 2026-05-19T12:30:08.950Z

Link: CVE-2026-8965

cve-icon Vulnrichment

Updated: 2026-05-20T15:36:54.556Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-19T14:16:52.930

Modified: 2026-05-20T17:51:46.440

Link: CVE-2026-8965

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-20T18:15:26Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor