Spoofing Vulnerability in Firefox from Mozilla
CVE-2026-100822

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100822?

A spoofing vulnerability exists in the Networking: HTTP component of Mozilla Firefox, which could allow an attacker to create misleading URLs or web content that could deceive users. This may lead to unauthorized actions or exposing sensitive information. Mozilla has addressed this issue in the Firefox ESR 153.4 and Firefox 157 releases, enhancing the security measures to prevent potential exploitation.

Affected Version(s)

Firefox 153.4

Firefox 157

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tomoya Nakanishi
.