MEDIUM

CVE-2026-12325

Mozilla Firefox 2026-06-16 CVSS v3.1
CVSS
6.5

Description

Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Summary dbcve.org

A denial-of-service vulnerability exists in the Graphics: ImageLib component of Firefox and Thunderbird. The flaw allows attackers to cause the browser or email client to crash via specially crafted image files processed by the ImageLib library. Successful exploitation results in application termination rather than code execution.

Mitigation

Upgrade affected installations to Firefox 152 (or ESR 140.12/115.37 per branch) or Thunderbird 152 (or 140.12) to remediate the vulnerability. Organizations should inventory all deployed Firefox and Thunderbird instances and deploy the patched versions.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

0.23%
Probability of exploitation in next 30 days
13.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE