CVE-2018-12401: Input Validation
Last updated 25 August 2025
Other sources
Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lead to denial of service (DOS) attacks.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-12401?
CVE-2018-12401 is a vulnerability in Firefox that could lead to denial of service (DOS) attacks.
How does CVE-2018-12401 affect Firefox?
CVE-2018-12401 affects Firefox versions prior to 63.
What is the severity of CVE-2018-12401?
The severity of CVE-2018-12401 is high, with a severity value of 7.5.
How can I fix CVE-2018-12401?
To fix CVE-2018-12401, update Firefox to version 63 or later.
Where can I find more information about CVE-2018-12401?
You can find more information about CVE-2018-12401 in the references provided: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1422456), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2018-26/), [CVE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12401).