Junglewise Threat Intelligence

CVE-2026-12318: Mozilla NSS incorrect boundary conditions in Libraries component

CVE-2026-12318 · Severity: info · CVSS 3.3 · Published 2026-06-16

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability exists in the Network Security Services (NSS) library used by the Firefox web browser. This issue involves incorrect boundary checks, which could potentially lead to minor stability issues or unexpected behavior when the browser processes certain data. Mozilla has released Firefox 152 to address this concern.

Technical details

A vulnerability categorized as 'incorrect boundary conditions' exists within the Libraries component of Mozilla's Network Security Services (NSS). The flaw is rooted in improper validation of data boundaries, which is a common precursor to buffer overflows or out-of-bounds reads/writes. While the specific impact is rated as low by Mozilla, such flaws typically allow for denial-of-service or potentially limited information disclosure depending on the specific memory context. The vulnerability is reachable via network-delivered content processed by the browser. It has been patched in Firefox version 152.

Affected products

  • Mozilla Firefox < 152
  • Mozilla Network Security Services (NSS)

Timeline

  • 2026-06-16: advisory: Mozilla Foundation Security Advisory 2026-57 published
  • 2026-06-16: patched: Fixed in Firefox 152

References

Related threats