Description
Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential instability or inconsistent rendering due to a race condition in the DOM content processes
Action: Apply patch
AI Analysis

Impact

A race condition within Mozilla’s DOM Content Processes component can cause rendering processes to enter an inconsistent state, potentially leading to application crashes. The vulnerability is identified as a race condition (CWE-366 and CWE-362 affecting process stability and user experience).

Affected Systems

The issue impacts both Mozilla Firefox and Mozilla Thunderbird. All releases prior to Firefox 156, Thunderbird 156, and the Firefox ESR 153.3 build are affected. Users running any of those older versions without the respective fixes are susceptible.

Risk and Exploitability

With a CVSS score of 7.5 the vulnerability is considered high severity. The EPSS score is <1%, indicating a very low probability of exploitation. It is not listed in CISA’s KEV catalog. While the description does not specify an explicit attack vector, the race condition could potentially be triggered by malicious content served to the browser or local files, but no public exploit is known.

Generated by OpenCVE AI on September 20, 2026 at 17:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to version 156 or later and install the corresponding ESR update 153.3.
  • Upgrade Mozilla Thunderbird to version 156 or later and install the corresponding ESR update 153.3.
  • For environments that cannot upgrade immediately, disable content processes by setting the preference 'browser.content_processes' to 0, reducing the race‑condition‑related instability until a patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 17:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-366
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

threat_severity

Moderate


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Race condition in the DOM: Content Processes component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-20T00:25:33.037Z

Reserved: 2026-09-15T12:34:02.764Z

Link: CVE-2026-92042

cve-icon Vulnrichment

Updated: 2026-09-20T00:25:26.380Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:16:55.630

Modified: 2026-10-05T17:52:09.030

Link: CVE-2026-92042

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T12:34:03Z

Links: CVE-2026-92042 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:15:17Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-366

    Race Condition within a Thread