PT-2026-38428 · Mozilla+1 · Firefox+1

·

CVE-2026-8090

·

Published

2026-05-07

·

Updated

2026-07-28

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 150.0.2 Firefox ESR versions prior to 140.10.2 Firefox ESR versions prior to 115.35.2 Thunderbird versions prior to 150.0.2 Thunderbird versions prior to 140.10.2
Description A use-after-free issue exists within the DOM Networking component. A use-after-free occurs when an application continues to use a pointer after it has been freed, which can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations Update to version 150.0.2 or newer. Update to version 140.10.2 or newer. Update to version 115.35.2 or newer. Update to version 150.0.2 or newer. Update to version 140.10.2 or newer.

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:19160
ALSA-2026:20566
ALSA-2026:20574
BDU:2026-07923
CVE-2026-8090
OESA-2026-2292
OESA-2026-2349
OESA-2026-2350
OESA-2026-2351
OESA-2026-2352
OPENSUSE-SU-2026:10720-1
OPENSUSE-SU-2026:10737-1
OPENSUSE-SU-2026:10738-1
OPENSUSE-SU-2026:21168-1
RHSA-2026:19160
RHSA-2026:20566
RHSA-2026:20574
RHSA-2026:21381
RHSA-2026:22325
RHSA-2026:22643
RHSA-2026:24508
RHSA-2026:24509
RHSA-2026:24510
RHSA-2026:24511
RHSA-2026:24516
RHSA-2026:24755
RHSA-2026:24983
RHSA-2026:25015
RHSA-2026:26174
RHSA-2026:26268
RHSA-2026:26269
RHSA-2026:26270
RHSA-2026:26521
RHSA-2026:26536
RHSA-2026:26539

Affected Products

Firefox
Red Os