Junglewise Threat Intelligence

CVE-2026-84132: Mozilla Firefox information disclosure in HTTP networking

CVE-2026-84132 · Severity: high · CVSS 7.5 · Published 2026-09-01

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox's HTTP networking component contains an information disclosure vulnerability that could allow attackers to expose sensitive data transmitted over HTTP connections. This affects Firefox web browsers used across many organizations and individual users. The vulnerability was patched in Firefox 155 and related products including Thunderbird 155.

Technical details

This vulnerability is classified as an information disclosure flaw in the Networking: HTTP component of Firefox. The precise attack vector and preconditions are not fully detailed in the available advisory summary, but the exposure allows unauthorized access to sensitive information. The vulnerability was identified by researcher Shu Takahashi and tracked as CVE-2026-84132. Mozilla addressed this issue in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2 releases.

Affected products

  • Mozilla Firefox before 155
  • Mozilla Firefox ESR before 153.2
  • Mozilla Thunderbird before 155
  • Mozilla Thunderbird ESR before 153.2

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2

References

Related threats