CVE-2026-8094
Critical · CVSS 9.8Mozilla Firefox / Thunderbird WebRTC — Improper Control of Code Generation (CWE-94) in WebRTC component
- CVSS
- 9.8
- nvd
- EPSS
- 0.45%
- 37th pct
- KEV
- No
- Class
- other
- CWE-94
Description
Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.
Search profile — drives PoC discovery
Symbols WebRTCRTCPeerConnectionmfsa2026-41mfsa2026-44bug2035939Firefox ESR 140.10.2Thunderbird 140.10.2
Keywords CVE-2026-8094Firefox WebRTC CWE-94mfsa2026-41mfsa2026-44Firefox ESR 140.10.2 exploitThunderbird 140.10.2 exploitWebRTC code injection Firefoxbugzilla 2035939 PoCRHSA-2026:19160RHSA-2026:20566
Versions: Firefox ESR < 140.10.2; Thunderbird < 140.10.2
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2035939
- https://www.mozilla.org/security/advisories/mfsa2026-41/
- https://www.mozilla.org/security/advisories/mfsa2026-44/
- https://access.redhat.com/errata/RHSA-2026:19160
- https://access.redhat.com/errata/RHSA-2026:20566
- https://access.redhat.com/errata/RHSA-2026:20574
- https://access.redhat.com/errata/RHSA-2026:21381
- https://access.redhat.com/errata/RHSA-2026:22325
- https://access.redhat.com/errata/RHSA-2026:22643
- https://access.redhat.com/errata/RHSA-2026:24508
- https://access.redhat.com/errata/RHSA-2026:24509
- https://access.redhat.com/errata/RHSA-2026:24510
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T18:30:14.000Z