Description
Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

A flaw was found in the Networking: HTTP component that allows the disclosure of unexpected data. The vulnerability can cause an attacker to obtain information that the client application should not reveal. This weakness is reflected by the common weakness identifiers CWE‑201 and CWE‑200.

Affected Systems

Mozilla’s Firefox browser versions earlier than 156 (including all ESR releases prior to 153.3) and Thunderbird versions earlier than 156 (including all ESR releases prior to 153.3) are affected. Versions 156 and newer for Firefox, ESR 153.3 and newer for Firefox ESR, and 156 and newer for Thunderbird, ESR 153.3 and newer for Thunderbird are not impacted. Users should verify that their installed Firefox and Thunderbird versions are at or above these fixed releases.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact. The EPSS score of < 1% and the absence from CISA’s KEV catalog suggest that the vulnerability is not currently widely exploited or nationally significant. However, because the flaw permits disclosure of potentially sensitive data, the risk to confidentiality is real. The attack vector is inferred as remote; an adversary could trigger the disclosure by sending crafted HTTP traffic to the interface.

Generated by OpenCVE AI on September 21, 2026 at 19:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Firefox to version 156 or newer, or apply the ESR 153.3 patch;
  • Update Thunderbird to version 156 or newer;
  • If a patch is temporarily unavailable, restrict or monitor outbound HTTP traffic from the affected client to prevent potential data leakage until an update can be applied.

Generated by OpenCVE AI on September 21, 2026 at 19:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-201
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

threat_severity

Moderate


Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Information disclosure in the Networking: HTTP component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-21T17:31:03.848Z

Reserved: 2026-09-15T12:34:04.846Z

Link: CVE-2026-92044

cve-icon Vulnrichment

Updated: 2026-09-21T17:30:07.745Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:16:55.860

Modified: 2026-10-05T17:51:05.473

Link: CVE-2026-92044

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T12:34:05Z

Links: CVE-2026-92044 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:45:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-201

    Insertion of Sensitive Information Into Sent Data