CVE-2026-84132
massInformation Disclosure in Mozilla Firefox and Thunderbird HTTP Networking
CVE-2026-84132 is an information-disclosure vulnerability (CWE-200) in the Networking: HTTP component of Mozilla Firefox and Mozilla Thunderbird. Because the flaw sits in the HTTP networking stack, it is triggered remotely through the client's handling of network traffic, and its CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) indicates it is exploitable over a network with low attack complexity and without privileges or user interaction. A successful attacker gains access to sensitive information processed by the affected client (high confidentiality impact), with no impact on integrity or availability. Users running Firefox before 155, Firefox ESR before 153.2, Thunderbird before 155, or Thunderbird before 153.2 are affected. There is currently no evidence of exploitation: no public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and EPSS assigns a low 0.3% probability (17th percentile) of exploitation within the next 30 days.
What to do: Upgrade all managed endpoints to Firefox 155 or Firefox ESR 153.2 (or later) and to Thunderbird 155 or Thunderbird 153.2 (or later), and verify installed versions through your device-management or EDR inventory. No specific workaround is documented in the available data, so updating is the primary mitigation; keep automatic updates enabled. Given the confidentiality-only impact and the absence of known exploitation, patching on your standard cadence is reasonable, with priority for users and hosts that handle sensitive information.
| mozilla firefox | before 155 |
| mozilla firefox_esr | before 153.2 |
| mozilla thunderbird | before 155 |
| mozilla thunderbird | before 153.2 (older 153.x branch) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.