CVE-2026-12325
Description
Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
Summary dbcve.org
A denial-of-service vulnerability exists in the Graphics: ImageLib component of Firefox and Thunderbird. The flaw allows attackers to cause the browser or email client to crash via specially crafted image files processed by the ImageLib library. Successful exploitation results in application termination rather than code execution.
Mitigation
Upgrade affected installations to Firefox 152 (or ESR 140.12/115.37 per branch) or Thunderbird 152 (or 140.12) to remediate the vulnerability. Organizations should inventory all deployed Firefox and Thunderbird instances and deploy the patched versions.