CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-12297

Critical · CVSS 9.6

Mozilla Firefox / Thunderbird — Sandbox escape via incorrect boundary conditions in Networking component (CWE-119 buffer boundary error)

CVSS
9.6
nvd
EPSS
0.39%
31th pct
KEV
No
Class
other
CWE-119, CWE-653

Description

Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Search profile — drives PoC discovery

Symbols sandbox escapeNetworkingboundary conditionsCWE-119mfsa2026-57mfsa2026-58mfsa2026-59mfsa2026-60bugzilla 2041610
Keywords CVE-2026-12297Firefox sandbox escapeThunderbird sandbox escapeFirefox Networking boundarymfsa2026-57mfsa2026-58mfsa2026-59mfsa2026-60Firefox 152 sandboxFirefox ESR 140.12Firefox ESR 115.37bugzilla 2041610buffer boundary networking firefox
Versions: Firefox < 152, Firefox ESR < 140.12, Firefox ESR < 115.37, Thunderbird < 152, Thunderbird < 140.12

References

Status: enriched · ingested 2026-06-19T00:00:04.000Z · profiled 2026-06-19T00:30:04.000Z