Mozilla Foundation Security Advisory 2021-37

Security Vulnerabilities fixed in Firefox 91.0.1 and Thunderbird 91.0.1

Announced
August 16, 2021
Impact
high
Products
Firefox, Thunderbird
Fixed in
  • Firefox 91.0.1
  • Thunderbird 91.0.1

#CVE-2021-29991: Header Splitting possible with HTTP/3 Responses

Reporter
Youssef Sammouda
Impact
high
Description

Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers using HTTP/3.

References