CVE-2026-0889: Denial-of-service in the DOM: Service Workers component
Published Jan 13, 2026
·Updated
Denial-of-service in the DOM: Service Workers component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
Affected Software
4 affected componentsFixes available
Mozilla Firefox<147
147
Mozilla Thunderbird<147
147
Mozilla Firefox<147.0
Mozilla Thunderbird<147.0
Event History
Jan 13, 2026
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Updated
via Mozilla·12:00 AM
Affected Software
CVE Published
via MITRE·01:30 PM
Data Sourced
via MITRE·01:30 PM
Description
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2026-0889?
CVE-2026-0889 is classified as a denial-of-service vulnerability in Firefox versions earlier than 147.
2
How do I fix CVE-2026-0889?
To fix CVE-2026-0889, update to Firefox version 147 or later.
3
What components are affected by CVE-2026-0889?
CVE-2026-0889 specifically affects the Service Workers component of the DOM in Firefox.
4
What versions of Firefox are vulnerable to CVE-2026-0889?
Firefox versions below 147 are vulnerable to CVE-2026-0889.
5
Can I still use Firefox if I have CVE-2026-0889?
Using an affected version of Firefox may expose you to denial-of-service risks, so it is recommended to update as soon as possible.