CVE-2026-2799
Critical · CVSS 9.8Firefox / Thunderbird — Use-after-free in DOM Core & HTML
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-416, CWE-416
Description
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
Search profile — drives PoC discovery
Symbols DOMCoreHTMLuse-after-freeCWE-416bug2014551mfsa2026-13mfsa2026-16
Keywords CVE-2026-2799Firefox 148Thunderbird 148use-after-free DOMmfsa2026-13mfsa2026-16bugzilla 2014551DOM Core HTML UAFFirefox UAF PoC
Versions: Firefox < 148, Thunderbird < 148
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2014551
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://access.redhat.com/security/cve/CVE-2026-2799
- https://bugzilla.redhat.com/show_bug.cgi?id=2442303
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2799.json
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T00:30:14.000Z