Junglewise Threat Intelligence

CVE-2026-2771: Mozilla Firefox and Thunderbird undefined behavior in DOM Core and HTML

CVE-2026-2771 · Severity: critical · CVSS 9.8 · Published 2026-02-24

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Red Hat, Mozilla.

Executive brief

A critical vulnerability has been identified in the core web-page processing engine of Firefox and Thunderbird. This flaw could allow an attacker to potentially execute unauthorized code or crash the application when a user visits a malicious website or opens a specially crafted email. Organizations should update their web browsers and email clients to the latest versions to protect against potential data theft or system compromise.

Technical details

A vulnerability classified as 'undefined behavior' exists within the DOM: Core & HTML component of Mozilla-based products. While the specific root cause is described generally as undefined behavior, CISA-ADP has associated it with an out-of-bounds read (CWE-125), and Red Hat indicates it may involve memory corruption. The attack vector is network-based and requires no special privileges, potentially allowing for remote code execution or a complete denial of service. The issue was discovered by a research team using AI-assisted fuzzing (Claude from Anthropic) and has been patched in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, and corresponding Thunderbird releases.

Affected products

  • Mozilla Firefox < 148
  • Mozilla Firefox ESR < 115.33, < 140.8
  • Mozilla Thunderbird < 148, < 140.8
  • Red Hat Enterprise Linux Server (v. 7 ELS) 7

Timeline

  • 2026-02-24: advisory: Mozilla Foundation Security Advisory published
  • 2026-02-24: patched: Fixed in Firefox 148 and ESR versions

References

Related threats