JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade firefox-x11Upgrade thunderbirdUpgrade firefox | Dec 15, 2025 | Dec 10, 2025 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade firefox | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade firefoxUpgrade firefox-debuginfoUpgrade firefox-debugsource | Jan 12, 2026 | Dec 9, 2025 |
| Debian | — | Upgrade thunderbirdUpgrade firefox-esr | Dec 12, 2025 | Dec 12, 2025 |
| Freebsd | — | Upgrade firefox-esrUpgrade firefoxUpgrade thunderbird | Jan 27, 2026 | Dec 11, 2025 |
| Mfsa2025 92 | — | Upgrade to Mozilla Firefox version 146.0 | Dec 10, 2025 | Dec 9, 2025 |
| Mfsa2025 93 | — | Upgrade to Mozilla Firefox ESR version 115.31 | Dec 10, 2025 | Dec 9, 2025 |
| Mfsa2025 94 | — | Upgrade to Mozilla Firefox ESR version 140.6 | Dec 10, 2025 | Dec 9, 2025 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 140.6 | Dec 11, 2025 | Dec 9, 2025 |
| Oracle_linux | — | Upgrade thunderbirdUpgrade firefox-x11Upgrade firefox | Dec 11, 2025 | Dec 9, 2025 |
| Redhat_linux | — | Upgrade firefox-debugsourceUpgrade firefox-x11Upgrade thunderbirdUpgrade firefoxNo solution existsUpgrade firefox-debuginfoUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsource | Dec 11, 2025 | Dec 9, 2025 |
| Rocky_linux | — | Upgrade thunderbirdUpgrade firefox-x11Upgrade firefoxUpgrade firefox-debugsourceUpgrade thunderbird-debuginfoUpgrade firefox-debuginfoUpgrade thunderbird-debugsource | Jan 6, 2026 | Jan 5, 2026 |
| Ubuntu | — | Upgrade thunderbird | Feb 4, 2026 | Feb 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub