CVE-2026-4719
7.5Mozilla · Firefox, Thunderbird
A boundary condition error in the Graphics: Text component of Mozilla Firefox and Thunderbird may lead to a denial of service.
Executive summary
A critical boundary condition vulnerability in Mozilla Firefox and Thunderbird allows unauthenticated attackers to cause a denial of service.
Vulnerability
The vulnerability involves incorrect boundary conditions within the Graphics: Text component. This flaw can be triggered by an unauthenticated remote attacker through network vectors without requiring user interaction.
Business impact
The flaw carries a CVSS score of 7.5, indicating a high severity risk due to its potential to disrupt critical business operations. A successful exploit results in an application crash, causing a denial of service that impacts user productivity and organizational continuity.
Remediation
Immediate Action: Organizations must update Mozilla Firefox and Thunderbird to version 149 or later, or to version 140.9 for Extended Support Release (ESR) users.
Proactive Monitoring: Security teams should monitor system logs for unusual application crashes or repeated process terminations involving the Graphics or Text rendering modules.
Compensating Controls: While no specific WAF rule can prevent this memory-level flaw, maintaining endpoint protection and restricting network access to untrusted content can reduce the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the high CVSS score and the potential for service disruption, administrators should prioritize patching these browser and mail client instances. Ensure that automated update mechanisms are enabled to capture the 149 or 140.9 releases immediately to eliminate this risk.
More Mozilla CVEs
Sources
Originally found and disclosed by Sajeeb Lohani, per the CVE Program record.