Description
Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service through memory corruption or application crash
Action: Immediate Patch
AI Analysis

Impact

The flaw stems from incorrect boundary checks in the Networking: HTTP component of Mozilla products, leading to an unchecked memory write (CWE-787). This can corrupt adjacent memory, potentially causing a crash or other unstable behavior, but there is no evidence of remote code execution.

Affected Systems

Mozilla Firefox and Mozilla Thunderbird installations older than version 156 are affected; the issue was addressed in Firefox 156 and Thunderbird 156.

Risk and Exploitability

With a CVSS score of 9.8, the severity is critical, yet the EPSS score is below 1% and the vulnerability is not listed in CISA KEV, implying a low likelihood of exploitation. The effect is primarily a denial of service through application crashes, and based on the description, it is inferred that the attack vector is the delivery of malformed HTTP traffic over a network connection.

Generated by OpenCVE AI on September 21, 2026 at 19:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 156 or later
  • Upgrade Thunderbird to version 156 or later
  • Enable automatic updates or plan an upgrade as soon as possible

Generated by OpenCVE AI on September 21, 2026 at 19:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-129

Wed, 16 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-129

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156. Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
References

Tue, 15 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156.
Title Incorrect boundary conditions in the Networking: HTTP component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-21T17:17:45.142Z

Reserved: 2026-09-15T12:33:56.532Z

Link: CVE-2026-92036

cve-icon Vulnrichment

Updated: 2026-09-21T17:17:22.044Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:16:54.960

Modified: 2026-10-05T17:58:31.083

Link: CVE-2026-92036

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-15T12:33:57Z

Links: CVE-2026-92036 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:30:15Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-787

    Out-of-bounds Write