CVE-2026-0888
published 2026-01-13CVE-2026-0888: Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.31%
23.3th percentile
Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 147.0-1 (sid) | firefox 147.0-1 (sid) |
| mozilla | firefox | < 147.0 | 147.0 |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 147.0 | 147.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
firefox: Information disclosure in the XML component
vendor_redhat·2026-01-13·CVSS 5.3
CVE-2026-0888 [MEDIUM] firefox: Information disclosure in the XML component
firefox: Information disclosure in the XML component
Information disclosure in the XML component. This vulnerability affects Firefox < 147 and Thunderbird < 147.
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue:
Information disclosure in the XML component
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Not affected
Package: rhel10/firefox-flatpak (Red Hat Enterprise Linux 10) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: firefox (Red Hat Enterprise Linux 8) - Not affected
Package: firefox (Red Hat Enterpr
Debian
CVE-2026-0888: firefox - Information disclosure in the XML component. This vulnerability affects Firefox ...
vendor_debian·2026·CVSS 5.3
CVE-2026-0888 [MEDIUM] CVE-2026-0888: firefox - Information disclosure in the XML component. This vulnerability affects Firefox ...
Information disclosure in the XML component. This vulnerability affects Firefox < 147 and Thunderbird < 147.
Scope: local
sid: resolved (fixed in 147.0-1)
Mozilla
Mozilla Foundation Security Advisory 2026-01: CVE-2026-0888
vendor_mozilla·CVSS 5.3
CVE-2026-0888 [MEDIUM] Mozilla Foundation Security Advisory 2026-01: CVE-2026-0888
Mozilla Foundation Security Advisory 2026-01
CVE: CVE-2026-0888
Product: Firefox
Impact: moderate
Fixed in: Firefox 147
Mozilla
Mozilla Foundation Security Advisory 2026-04: CVE-2026-0888
vendor_mozilla·CVSS 5.3
CVE-2026-0888 [MEDIUM] Mozilla Foundation Security Advisory 2026-04: CVE-2026-0888
Mozilla Foundation Security Advisory 2026-04
CVE: CVE-2026-0888
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 147
VulDB
Mozilla Firefox up to 146 XML information disclosure (EUVD-2026-2079 / WID-SEC-2026-0090)
vuldb·2026-06-12·CVSS 5.3
CVE-2026-0888 [MEDIUM] Mozilla Firefox up to 146 XML information disclosure (EUVD-2026-2079 / WID-SEC-2026-0090)
A vulnerability was found in Mozilla Firefox up to 146. It has been classified as problematic. Affected by this issue is some unknown functionality of the component XML Component. The manipulation leads to information disclosure.
This vulnerability is listed as CVE-2026-0888. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
OSV
CVE-2026-0888: Information disclosure in the XML component
osv·2026-01-13·CVSS 5.3
CVE-2026-0888 [MEDIUM] CVE-2026-0888: Information disclosure in the XML component
Information disclosure in the XML component. This vulnerability affects Firefox < 147 and Thunderbird < 147.
GHSA
GHSA-94r2-4g95-pg9m: Information disclosure in the XML component
ghsa_unreviewed·2026-01-13
CVE-2026-0888 [MEDIUM] CWE-200 GHSA-94r2-4g95-pg9m: Information disclosure in the XML component
Information disclosure in the XML component. This vulnerability affects Firefox < 147.
No detection rules found.
No public exploits indexed.
2026-01-13
Published