Description
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Mitigation Bypass
Action: Patch
AI Analysis

Impact

This vulnerability originates in the DOM networking component of Mozilla’s browsers and the Thunderbird mail client. It allows an attacker to craft content that fools the component into treating a network request as if it came from a trusted origin, effectively bypassing the browser‑level restrictions that normally block such traffic. Because the flaw deals with improperly enforced network‑related safeguards, it can lead to delivery of malicious payloads or data that should normally be blocked, although the CVE text does not state the exact downstream consequences. The impact focuses on the loss of the protection that the network component is supposed to enforce.

Affected Systems

Firefox versions before 156 and Firefox ESR releases older than 153.3, and Thunderbird builds earlier than 156 or ESR 153.3 remain vulnerable until upgraded to the specified fixed releases.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity, while the EPSS score of <1% shows a very low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the most likely attack vector involves a malicious web page or email message that contains crafted DOM operations. Attackers would need the victim to view or open the engineered content, after which the browser or client might process otherwise disallowed network requests, potentially enabling further malicious activity. The risk is therefore high if the user visits untrusted content, but exploitation likelihood remains low.

Generated by OpenCVE AI on September 21, 2026 at 20:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 156 or later, or to Firefox ESR 153.3 or newer as per Mozilla's advisory.
  • Upgrade Thunderbird to version 156 or later, or to Thunderbird ESR 153.3 or newer.
  • If you must continue using an affected version, configure the application to enforce stricter content security policies and consider disabling vulnerable DOM networking APIs through policy or extensions to reduce the attack surface.

Generated by OpenCVE AI on September 21, 2026 at 20:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Sun, 20 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-284

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-807
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

threat_severity

Moderate


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Mitigation bypass in the DOM: Networking component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-21T17:27:51.012Z

Reserved: 2026-09-15T12:34:01.740Z

Link: CVE-2026-92041

cve-icon Vulnrichment

Updated: 2026-09-21T17:27:39.827Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:16:55.513

Modified: 2026-10-05T17:52:39.340

Link: CVE-2026-92041

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T12:34:02Z

Links: CVE-2026-92041 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T21:00:07Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure

  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision