CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-4700

Critical · CVSS 9.8

Mozilla Firefox / Thunderbird — Authentication bypass via HTTP request smuggling / mitigation bypass (CWE-288, CWE-444)

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
NVD-CWE-noinfo, CWE-288, CWE-444

Description

Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Search profile — drives PoC discovery

Symbols Networking::HTTPnsHttpHandlernsHttpChannelmfsa2026-20mfsa2026-22mfsa2026-23mfsa2026-24bug2003766
Keywords CVE-2026-4700Firefox HTTP mitigation bypassFirefox 149 authentication bypassCWE-288 FirefoxCWE-444 HTTP request smuggling FirefoxThunderbird HTTP bypassmfsa2026-20bugzilla 2003766Firefox ESR 140.9 bypass
Versions: Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, Thunderbird < 140.9

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z