JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade firefox-x11Upgrade firefoxUpgrade thunderbird | Dec 15, 2025 | Dec 10, 2025 |
| Amazon Linux Ami 2 | — | Upgrade firefoxUpgrade thunderbird | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade firefoxUpgrade firefox-debuginfoUpgrade firefox-debugsource | Jan 12, 2026 | Dec 9, 2025 |
| Debian | — | Upgrade firefox-esrUpgrade thunderbird | Dec 12, 2025 | Dec 12, 2025 |
| Freebsd | — | Upgrade firefoxUpgrade firefox-esrUpgrade thunderbird | Jan 27, 2026 | Dec 11, 2025 |
| Mfsa2025 92 | — | Upgrade to Mozilla Firefox version 146.0 | Dec 10, 2025 | Dec 9, 2025 |
| Mfsa2025 93 | — | Upgrade to Mozilla Firefox ESR version 115.31 | Dec 10, 2025 | Dec 9, 2025 |
| Mfsa2025 94 | — | Upgrade to Mozilla Firefox ESR version 140.6 | Dec 10, 2025 | Dec 9, 2025 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 140.6 | Dec 11, 2025 | Dec 9, 2025 |
| Oracle_linux | — | Upgrade thunderbirdUpgrade firefox-x11Upgrade firefox | Dec 11, 2025 | Dec 9, 2025 |
| Redhat_linux | — | Upgrade thunderbird-debuginfoUpgrade firefox-x11No solution existsUpgrade thunderbird-debugsourceUpgrade firefoxUpgrade firefox-debuginfoUpgrade thunderbirdUpgrade firefox-debugsource | Dec 11, 2025 | Dec 9, 2025 |
| Rocky_linux | — | Upgrade thunderbirdUpgrade firefox-x11Upgrade firefoxUpgrade thunderbird-debuginfoUpgrade firefox-debugsourceUpgrade thunderbird-debugsourceUpgrade firefox-debuginfo | Jan 6, 2026 | Jan 5, 2026 |
| Ubuntu | — | Upgrade thunderbird | Feb 4, 2026 | Feb 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub