Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers using HTTP/3. This vulnerability affects Firefox < 91.0.1 and Thunderbird < 91.0.1.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade librewolfUpgrade thunderbirdUpgrade firefox | Aug 22, 2024 | Nov 3, 2021 |
| Mfsa2021 37 | — | Upgrade to Mozilla Firefox version 91.0.1Upgrade to the latest version of Mozilla Firefox | Aug 18, 2021 | Aug 16, 2021 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 91.0.1 | Aug 18, 2021 | Aug 16, 2021 |
| Oracle Solaris | — | Upgrade web/browser/firefox to version 91.3.0-11.4.40.0.1.107.1 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 91.3.0-11.4.40.0.1.107.1 on Solaris 11.4Upgrade mail/thunderbird to version 91.3.0-11.4.40.0.1.107.1 on Solaris 11.4 | Dec 13, 2021 | Nov 3, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 3, 2021 |
| Suse | — | Upgrade MozillaFirefox-branding-SLEDUpgrade rust-cbindgenUpgrade MozillaFirefoxUpgrade mozillafirefox-branding-sleUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-commonUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations-commonUpgrade mozillafirefox-branding-upstreamUpgrade MozillaThunderbird-translations-otherUpgrade MozillaFirefox-translations-other | Sep 23, 2021 | Aug 19, 2021 |
| Ubuntu | — | Upgrade firefoxUpgrade thunderbird | Aug 20, 2021 | Aug 19, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub