AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-2786

LOW · CVSS 2.6 EPSS 1.77%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-06-02 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 2.6. It affects Firefox. It may be remotely exploitable.

CVE
CVE-2006-2786
Severity
LOW
CVSS
2.6
EPSS
1.77%
Firefox

Original NVD Description

HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites via (1) invalid HTTP response headers with spaces between the header name and the colon, which might not be ignored in some cases, or (2) HTTP 1.1 headers through an HTTP 1.0 proxy, which are ignored by the proxy but processed by the client.