CVE-2026-2801 is a high-severity vulnerability (CVSS 7.5) stemming from incorrect boundary conditions within the JavaScript: WebAssembly component. This flaw impacts Mozilla Firefox versions prior to 148 and Mozilla Thunderbird versions prior to 148. The vulnerability is network-exploitable with low attack complexity, allowing for a denial-of-service impact without requiring user interaction or elevated privileges. While there is no evidence of active exploitation, nor are there known public exploits or Metasploit modules, the vulnerability has garnered some community discussion, with three mentions across social media platforms.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 148.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | ||
< 148.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.