Mozilla · Firefox · CVE-2026-4700
**Name of the Vulnerable Software and Affected Versions**
Firefox versions prior to 149
Firefox ESR versions prior to 140.9
Thunderbird versions prior to 149
Thunderbird versions prior to 140.9
**Description**
A mitigation bypass exists in the Networking: HTTP component. This issue could allow bypassing existing security measures.
**Recommendations**
Update Firefox to version 149 or later.
Update Firefox ESR to version 140.9 or later.
Update Thunderbird to version 149 or later.
Update Thunderbird to version 140.9 or later.