CVE-2026-0888: Information disclosure in the XML component
Published Jan 13, 2026
·Updated
Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
Affected Software
4 affected componentsFixes available
Mozilla Firefox<147
147
Mozilla Thunderbird<147
147
Mozilla Firefox<147.0
Mozilla Thunderbird<147.0
Event History
Jan 13, 2026
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Updated
via Mozilla·12:00 AM
Affected Software
CVE Published
via MITRE·01:30 PM
Data Sourced
via MITRE·01:30 PM
Description
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2026-0888?
The severity of CVE-2026-0888 is classified as medium due to its potential for information disclosure.
2
How do I fix CVE-2026-0888?
To fix CVE-2026-0888, update Firefox to version 147 or later.
3
Who is affected by CVE-2026-0888?
CVE-2026-0888 affects users of Firefox versions prior to 147.
4
What type of vulnerability is CVE-2026-0888?
CVE-2026-0888 is an information disclosure vulnerability in the XML component of Firefox.
5
Is CVE-2026-0888 patched in the latest Firefox version?
Yes, CVE-2026-0888 is patched in Firefox version 147.