← All CVEs

CVE-2026-4689

critical · 10

Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

10
CVSS
0.7%
EPSS (exploit prob.)
50th
EPSS percentile
2026-03-24
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-190CWE-754CWE-120

Affected products

VendorProductAffected versions
mozillafirefox< 115.34.0
mozillafirefox< 149.0
mozillafirefox>= 128.0, < 140.9.0
mozillathunderbird< 140.9.0
mozillathunderbird< 149.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-4689