CVE-2026-4714 is a high-severity vulnerability (CVSS 7.5) affecting Mozilla Firefox, Firefox ESR, and Thunderbird, specifically versions prior to 149 and 140.9 respectively. The flaw is due to incorrect boundary conditions within the Audio/Video component. This network-exploitable vulnerability has low attack complexity and could lead to a high impact on availability, likely resulting in a denial of service. There is currently no evidence of active exploitation, no public exploit code available, and community discussion surrounding this CVE is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 140.9.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 149.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.