Description
Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A denial‑of‑service flaw exists in the Widget component of Mozilla Firefox and Mozilla Thunderbird. The bug triggers uncontrolled resource consumption whenever the Widget process is invoked, which can lead to application unresponsiveness or crash. The impact is confined to the client‑side software and presents a high‑severity risk for users who depend on uninterrupted browser operation.

Affected Systems

All Mozilla Firefox releases prior to version 154, all Firefox ESR releases older than 153.1, all Mozilla Thunderbird releases earlier than 154, and all Thunderbird ESR releases older than 153.1 are affected. The fix is deployed starting with Firefox 154 / ESR 153.1 and Thunderbird 154 / ESR 153.1; all intermediate releases remain vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates a high‑severity denial‑of‑service vulnerability, while the EPSS score of < 1% and absence from the CISA KEV catalog suggest a low probability of exploitation in the wild. The attack vector is not explicitly stated in the CVE description; it is inferred that an attacker would need to trigger the Widget component, possibly via locally privileged actions or by delivering content that causes the widget to load. No publicly disclosed exploit code is linked to this issue and the vulnerability remains unexploited at the time of analysis.

Generated by OpenCVE AI on August 21, 2026 at 18:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to version 154 or later (or ESR 153.1+).
  • Upgrade Mozilla Thunderbird to version 154 or later (or ESR 153.1+).
  • If immediate upgrade is not possible, disable or restrict Widget component usage through application settings or extensions.

Generated by OpenCVE AI on August 21, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Fri, 21 Aug 2026 12:15:00 +0000


Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770

Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
References

Tue, 18 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
Title Denial-of-service in the Widget component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-20T17:21:37.388Z

Reserved: 2026-08-17T11:59:10.459Z

Link: CVE-2026-74982

cve-icon Vulnrichment

Updated: 2026-08-20T15:37:49.863Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T13:17:37.253

Modified: 2026-08-25T16:11:04.540

Link: CVE-2026-74982

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-18T12:23:40Z

Links: CVE-2026-74982 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T18:30:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling