VulnerabilityModified
CVE-2026-12307
This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
MEDIUM 5.3EPSS 0.26%
Does this matter?
Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.
Description
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.26% probability · 18th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- mozilla/firefox · mozilla/thunderbird
- Source
- security@mozilla.org
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2038133Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2026-57/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-58/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-60/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-61/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.