CVE-2026-100773

EUVD-2026-88925
Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
mozillaCNA
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
mozillafirefox
𝑥
< 157
CNA
mozillafirefox_esr
𝑥
< 115.42
CNA
mozillafirefox_esr
116.0.0 ≤
𝑥
< 140.17
CNA
mozillafirefox_esr
141.0.0 ≤
𝑥
< 153.4
CNA
Debian logo
Debian Releases
Debian Product
Codename
firefox
sid
vulnerable
firefox-esr
bookworm
vulnerable
bookworm (security)
vulnerable
forky
vulnerable
sid
vulnerable
trixie
vulnerable
trixie (security)
vulnerable