Description
Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Published: 2026-04-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: DNS Vulnerability
Action: Immediate Update
AI Analysis

Impact

Other issue in the Networking: DNS component was reported, affecting Mozilla Firefox and Mozilla Thunderbird. The description does not disclose the flaw’s exact nature, so the precise impact remains unclear. However, as a core networking component, the vulnerability could potentially influence DNS resolution, leading to incorrect name resolution, denial‑of-service, or traffic redirection. These assertions are inferred rather than directly stated in the input. The CWE identifiers reflect weaknesses in input validation, cross‑site request forgery, resource exhaustion, and privilege validation, which together could allow an attacker to manipulate DNS queries, forge data, exhaust system resources, or elevate privileges if exploited.

Affected Systems

Mozilla Firefox and Mozilla Thunderbird are affected. The flaw was fixed in version 150 of both products, so versions prior to 150 are potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is less than 1%, pointing to a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The lack of public exploitation evidence combined with a moderate CVSS suggests a cautious but not urgent stance. Attackers would likely need to deliver malicious DNS queries or forged responses to a victim’s system over the network, exploiting weaknesses in input validation and privilege checks listed in the CWE identifiers. Because the flaw resides in a fundamental DNS component, successful exploitation could compromise name resolution, data integrity, and availability of the affected software.

Generated by OpenCVE AI on April 22, 2026 at 19:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Mozilla Firefox and Thunderbird releases (version 150 or newer) to apply the fix for the DNS component flaw.
  • If an immediate upgrade is not possible, configure the browser to use a trusted external DNS resolver or enable DNSSEC validation to reduce exposure to manipulated DNS responses.
  • Monitor system logs for anomalous DNS traffic or repeated resolution failures, and use network filtering to limit outbound DNS queries from the affected applications.

Generated by OpenCVE AI on April 22, 2026 at 19:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Wed, 22 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-676
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 22 Apr 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150. Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Weaknesses CWE-20
CWE-352
CWE-400
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Tue, 21 Apr 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Description Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150.
Title Other issue in the Networking: DNS component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-04-21T23:35:12.791Z

Reserved: 2026-04-21T12:41:08.101Z

Link: CVE-2026-6777

cve-icon Vulnrichment

Updated: 2026-04-21T17:17:33.129Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-21T13:16:23.430

Modified: 2026-04-22T15:08:29.453

Link: CVE-2026-6777

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-04-21T12:41:08Z

Links: CVE-2026-6777 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T19:45:25Z