Description
Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.
Published: 2026-04-07
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

Memory safety bugs were discovered in several Mozilla products, including Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1, and Thunderbird 149.0.1. These defects may cause memory corruption, and it is presumed that with sufficient effort they could be leveraged to execute arbitrary code. The vulnerability carries a CVSS score of 9.8, indicating a severe impact on confidentiality, integrity, and availability if exploited.

Affected Systems

Mozilla Firefox and Thunderbird are affected. The specific affected builds are Firefox ESR 115.34.0 and 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1, and Thunderbird 149.0.1. The issue has already been fixed in the following releases: Firefox 149.0.2, Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.

Risk and Exploitability

The vulnerability scores an EPSS of less than 1%, implying a low probability of exploitation in the wild. It is not listed in the CISA Known Exploited Vulnerabilities catalog. The lack of publicly documented exploit code and the nature of the bug suggest that the attack vector would most likely be local or require user interaction, although remote exploitation cannot be definitively ruled out without additional information. The high CVSS score reflects the potential for arbitrary code execution if successfully abused.

Generated by OpenCVE AI on April 13, 2026 at 16:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 149.0.2 or later and ensure ESR 115.34.1 and 140.9.1 are installed
  • Upgrade Thunderbird to version 149.0.2 or later and ensure ESR 140.9.1 is installed

Generated by OpenCVE AI on April 13, 2026 at 16:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4526-1 firefox-esr security update
Debian DLA Debian DLA DLA-4534-1 thunderbird security update
Debian DSA Debian DSA DSA-6202-1 firefox-esr security update
Debian DSA Debian DSA DSA-6211-1 thunderbird security update
History

Thu, 16 Apr 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mozilla:firefox:115.34.0:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:140.9.0:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:149.0.1:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:140.9.0:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:149.0.1:*:*:*:-:*:*:*

Mon, 13 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Description Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 149.0.2, Firefox ESR < 115.34.1, Firefox ESR < 140.9.1, Thunderbird < 149.0.2, and Thunderbird < 140.9.1. Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.

Wed, 08 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Mozilla firefox Esr
Mozilla thunderbird
Vendors & Products Mozilla
Mozilla firefox
Mozilla firefox Esr
Mozilla thunderbird

Wed, 08 Apr 2026 12:30:00 +0000


Tue, 07 Apr 2026 20:45:00 +0000

Type Values Removed Values Added
Description Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 149.0.2, Firefox ESR < 115.34.1, and Firefox ESR < 140.9.1. Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 149.0.2, Firefox ESR < 115.34.1, Firefox ESR < 140.9.1, Thunderbird < 149.0.2, and Thunderbird < 140.9.1.
References

Tue, 07 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Description Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 149.0.2, Firefox ESR < 115.34.1, and Firefox ESR < 140.9.1.
Title Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2
Weaknesses CWE-119
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Mozilla Firefox Firefox Esr Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-04-13T13:51:32.565Z

Reserved: 2026-04-07T12:43:11.413Z

Link: CVE-2026-5731

cve-icon Vulnrichment

Updated: 2026-04-07T14:10:54.663Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-07T13:16:47.347

Modified: 2026-04-16T18:59:46.350

Link: CVE-2026-5731

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-07T12:43:11Z

Links: CVE-2026-5731 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-14T16:41:04Z

Weaknesses