Description
Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A malformed SVG file can trigger a denial‑of‑service condition, causing the application to abort or crash. The flaw is an input validation weakness that leads to resource exhaustion, matching the description for CWE-770. The incident would interrupt user sessions but does not provide confidentiality or integrity compromise.

Affected Systems

The issue affects Mozilla Firefox and Thunderbird browsers. Versions impacted include Firefox 156 and Firefox ESR 153.3, as well as Thunderbird 156 and Thunderbird 153.3, and earlier releases that remain vulnerable until they upgrade.

Risk and Exploitability

The exploit requires an attacker to deliver a specially crafted SVG to the target, likely through a web page or email attachment. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating opportunistic exploitation. With a CVSS score of 6.5, the risk is moderate; the flaw causes crashes but the likelihood of exploitation remains low.

Generated by OpenCVE AI on September 20, 2026 at 16:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Firefox 156 or later (or ESR 153.3) and Thunderbird 156 or later.
  • Close any untrusted SVG files before opening them.
  • Regularly install security updates from Mozilla and monitor advisories for related patches.

Generated by OpenCVE AI on September 20, 2026 at 16:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

threat_severity

Low


Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Denial-of-service in the SVG component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-20T00:24:23.002Z

Reserved: 2026-09-15T12:34:38.753Z

Link: CVE-2026-92077

cve-icon Vulnrichment

Updated: 2026-09-20T00:24:19.134Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:17:03.323

Modified: 2026-10-05T19:21:22.490

Link: CVE-2026-92077

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-15T12:34:39Z

Links: CVE-2026-92077 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:00:13Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling