CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-4691

Critical · CVSS 9.8

Firefox / Thunderbird — Use-after-free in CSS Parsing and Computation

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-416, CWE-416, CWE-825

Description

Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Search profile — drives PoC discovery

Symbols CSS ParsingCSS ComputationCSSParserCSSValueStyleSheetComputedStylensCSSValueRuleProcessorServoStyleSetGeckoStyleContextmfsa2026-20mfsa2026-21mfsa2026-22mfsa2026-23bug2017512
Keywords CVE-2026-4691Firefox use-after-free CSSThunderbird use-after-free CSSFirefox 149 UAFFirefox ESR 115.34Firefox ESR 140.9Thunderbird 149Thunderbird 140.9CSS parsing use-after-free PoCmfsa2026-20CWE-416 Firefox CSSMozilla CSS computation UAF
Versions: Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, Thunderbird < 140.9

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z