CVE-2026-0888Sensitive Information Exposure in Mozilla Firefox

Severity
5.3MEDIUMNVD
EPSS
0.0%
top 97.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13

Description

Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDmozilla/firefox< 147.0
NVDmozilla/thunderbird< 147.0

🔴Vulnerability Details

3
CVEList
Information disclosure in the XML component2026-01-13
OSV
CVE-2026-0888: Information disclosure in the XML component2026-01-13
GHSA
GHSA-94r2-4g95-pg9m: Information disclosure in the XML component2026-01-13

📋Vendor Advisories

4
Red Hat
firefox: Information disclosure in the XML component2026-01-13
Debian
CVE-2026-0888: firefox - Information disclosure in the XML component. This vulnerability affects Firefox ...2026
Mozilla
Mozilla Foundation Security Advisory 2026-01: CVE-2026-0888
Mozilla
Mozilla Foundation Security Advisory 2026-04: CVE-2026-0888

🕵️Threat Intelligence

1
Wiz
CVE-2026-0888 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-0888 — Sensitive Information Exposure | cvebase