Executive brief
A security vulnerability has been identified in the HTTP networking component of Mozilla Firefox and Thunderbird. This flaw could allow an attacker to bypass built-in security mitigations, potentially leading to unauthorized access or data compromise. Users should update their browsers and email clients to the latest versions to protect their systems and data.
Technical details
A mitigation bypass vulnerability was identified in the Networking: HTTP component of Mozilla Firefox and Thunderbird. The vulnerability is characterized by inconsistent interpretation of HTTP requests (HTTP Request/Response Smuggling) or authentication bypass using an alternate path. An unauthenticated attacker can exploit this over the network to bypass security controls. While Mozilla rated the impact as 'moderate', NVD and CISA-ADP have assigned a CVSS score of 9.8 (Critical) due to the potential for high impact on confidentiality, integrity, and availability. The issue is resolved in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Affected products
- Mozilla Firefox < 149
- Mozilla Firefox ESR < 140.9
- Mozilla Thunderbird < 149
- Mozilla Thunderbird ESR < 140.9
- Red Hat Enterprise Linux Server 7 ELS
- Red Hat Enterprise Linux AppStream EUS 10.0
Timeline
- 2026-03-24: advisory: Mozilla published security advisories MFSA2026-20 and MFSA2026-22.
- 2026-03-24: patched: Fixed versions released for Firefox and Thunderbird.
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2003766
- https://www.mozilla.org/security/advisories/mfsa2026-20/
- https://www.mozilla.org/security/advisories/mfsa2026-22/
- https://www.mozilla.org/security/advisories/mfsa2026-23/
- https://www.mozilla.org/security/advisories/mfsa2026-24/
- https://access.redhat.com/errata/RHSA-2026:5930
- https://access.redhat.com/errata/RHSA-2026:5931