Executive brief
Firefox and Thunderbird include a Security component that processes cryptographic and validation operations. A denial-of-service vulnerability in this component allows attackers to crash or hang the browser/email client without requiring user interaction, affecting availability and productivity. Mozilla addressed this issue in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Technical details
This is a denial-of-service vulnerability in the Security component of Firefox and Thunderbird. The vulnerability allows an attacker to trigger a crash or hang condition in the Security component, resulting in denial of service to the affected applications. The attack vector is network-based, and the vulnerability does not require prior authentication. While the specific root cause is not fully disclosed in the available references, the CVSS score of 6.5 indicates a moderate-to-high severity impact on availability. Patches are available in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird before 153.3
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, Thunderbird 153.3