CVE-2026-4700

CRITICAL

Mitigation bypass in the Networking: HTTP component

Title source: cna
STIX 2.1

Description

Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

References (33)

Core 33
Core References

Scores

CVSS v3 9.8
EPSS 0.0046
EPSS Percentile 37.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-288 CWE-444
Status published
Products (10)
mozilla/firefox < 140.9.0
mozilla/firefox < 149.0
Mozilla/Firefox 140.9 - 140.*
Mozilla/Firefox 149
Mozilla/Firefox unspecified - 149
Mozilla/Firefox ESR unspecified - 140.9
Mozilla/Thunderbird 140.9 - 140.*
Mozilla/Thunderbird 149
Mozilla/Thunderbird unspecified - 140.9
Mozilla/Thunderbird unspecified - 149
Published Mar 24, 2026
Tracked Since Mar 24, 2026