Description
Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Published: 2026-04-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential for memory corruption due to incorrect boundary handling in NSS
Action: Immediate Update
AI Analysis

Impact

This vulnerability arises from incorrect boundary checks in the Libraries component of the NSS toolkit, which can lead to memory corruption. The flaw aligns with CWE‑754 (boundary condition error) and CWE‑787 (buffer overread), indicating that misinterpreted size handling could corrupt or expose memory contents. Based on the description, it is inferred that exploiting the vulnerability would require manipulating NSS memory operations, which may be possible through local privilege escalation or exploitation of other components that interact with NSS.

Affected Systems

Mozilla Firefox and Thunderbird builds that include the unpatched NSS library are affected. For Firefox, all versions before 150, and ESR releases prior to 115.35 and 140.10 are vulnerable. For Thunderbird, all versions before 150, and ESR releases before 115.35 and 140.10 are impacted.

Risk and Exploitability

The CVSS score of 7.5 indicates significant impact, while the EPSS score of less than 1% shows low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector likely involves local exploitation of NSS memory operations, possibly requiring privileged code or other components that interface with NSS. With no publicly reported exploits, the overall risk is moderate but high enough to warrant immediate remediation.

Generated by OpenCVE AI on April 22, 2026 at 19:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to version 150 or later
  • Upgrade Firefox ESR to 115.35, 140.10 or later
  • Upgrade Mozilla Thunderbird to version 150 or later
  • Upgrade Thunderbird ESR to 115.35, 140.10 or later
  • Monitor Mozilla security advisories for emergency patches or temporary mitigations until the upgrade can be performed

Generated by OpenCVE AI on April 22, 2026 at 19:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6225-1 firefox-esr security update
History

Wed, 22 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
Vendors & Products Mozilla thunderbird

Wed, 22 Apr 2026 12:15:00 +0000


Wed, 22 Apr 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Wed, 22 Apr 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Wed, 22 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, and Firefox ESR 140.10. Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Apr 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, and Firefox ESR 140.10.
Title Incorrect boundary conditions in the Libraries component in NSS
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-04-21T23:35:07.125Z

Reserved: 2026-04-21T12:41:04.255Z

Link: CVE-2026-6772

cve-icon Vulnrichment

Updated: 2026-04-21T19:37:59.008Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-21T13:16:23.007

Modified: 2026-04-22T16:04:22.270

Link: CVE-2026-6772

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-04-21T12:41:04Z

Links: CVE-2026-6772 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T19:45:25Z

Weaknesses