Executive brief
Firefox and Thunderbird browsers contain an information disclosure vulnerability in the HTTP networking component that could expose sensitive data. The flaw allows attackers to access confidential information during network communication, potentially exposing user data or session credentials. This affects multiple versions and was patched in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Technical details
CVE-2026-92044 is an information disclosure vulnerability in the Networking: HTTP component of Firefox and related Mozilla products. The vulnerability occurs due to improper handling of HTTP protocol data, allowing sensitive information to be exposed during network communication. An attacker with network-level access could potentially intercept or access confidential data without requiring user authentication. The flaw was identified and patched across multiple Mozilla products in September 2026.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird before 153.3
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3