CVE-2026-12330: Incorrect boundary conditions in the Internationalization component
Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 140.12.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.12 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.37 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.12 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.37 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.12
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-12289
- CVE-2026-12290
- CVE-2026-12291
- CVE-2026-12292
- CVE-2026-12294
- CVE-2026-12295
- CVE-2026-12298
- CVE-2026-12296
- CVE-2026-12297
- CVE-2026-12299
- CVE-2026-12329
- CVE-2026-12302
- CVE-2026-12304
- CVE-2026-12305
- CVE-2026-12306
- CVE-2026-12307
- CVE-2026-12308
- CVE-2026-12309
- CVE-2026-12310
- CVE-2026-12311
- CVE-2026-12312
- CVE-2026-12313
- CVE-2026-12314
- CVE-2026-12315
- CVE-2026-12330
- CVE-2026-12324
- CVE-2026-12325
- CVE-2026-12327
- CVE-2026-12328
Frequently Asked Questions
What is the severity of CVE-2026-12330?
CVE-2026-12330 has a medium severity rating of 5.4 according to the CVSS 3.1 score.
How do I fix CVE-2026-12330?
To fix CVE-2026-12330, update to Firefox ESR 140.12, Firefox ESR 115.37, or Thunderbird 140.12.
What types of software does CVE-2026-12330 affect?
CVE-2026-12330 affects Mozilla Firefox ESR and Mozilla Thunderbird.
What is the risk of exploiting CVE-2026-12330?
The risk associated with CVE-2026-12330 is rated as moderate with a risk score of 34.
What is the nature of the issue in CVE-2026-12330?
CVE-2026-12330 involves incorrect boundary conditions in the Internationalization component, leading to potential buffer overflow.