Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers using HTTP/3. This vulnerability affects Firefox < 91.0.1 and Thunderbird < 91.0.1.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade librewolfUpgrade thunderbirdUpgrade firefox | Aug 22, 2024 | Nov 3, 2021 |
| Mfsa2021 37 | — | Upgrade to Mozilla Firefox version 91.0.1 | Aug 18, 2021 | Aug 16, 2021 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 91.0.1 | Aug 18, 2021 | Aug 16, 2021 |
| Oracle Solaris | — | Upgrade mail/thunderbird to version 91.3.0-11.4.40.0.1.107.1 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 91.3.0-11.4.40.0.1.107.1 on Solaris 11.4Upgrade web/browser/firefox to version 91.3.0-11.4.40.0.1.107.1 on Solaris 11.4 | Dec 13, 2021 | Nov 3, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 3, 2021 |
| Suse | — | Upgrade MozillaFirefox-translations-commonUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations-otherUpgrade mozillafirefox-branding-upstreamUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-develUpgrade MozillaThunderbird-translations-commonUpgrade mozillafirefox-branding-sleUpgrade MozillaFirefox-branding-SLEDUpgrade rust-cbindgen | Sep 23, 2021 | Aug 19, 2021 |
| Ubuntu | — | Upgrade thunderbirdUpgrade firefox | Aug 20, 2021 | Aug 19, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub